Nutex Health Tells the SEC Hackers Walked Off With Data From Its Servers

The Nasdaq-listed hospital operator, which runs 28 facilities across 12 states, says the stolen files may include private information but has not yet pinned down whose.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A hospital corridor with computer servers and networking equipment visible through glass walls, with several workstations showing alert notifications on their s
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Nutex Health disclosed a data breach to the U.S. Securities and Exchange Commission, saying an unauthorised third party accessed and copied information from its servers.
  • The company runs 28 hospitals and clinics across 12 states and trades on the Nasdaq under NUTX.
  • As of 24 August, Nutex says it has found no material impact on its operations or financial systems.
  • The company hasn't yet worked out whether patients, staff or business partners are affected.
  • No hacking group has publicly claimed the attack.

Nutex Health, a for-profit hospital operator listed on the Nasdaq, has told U.S. Regulators that hackers broke into its servers and copied data out.

The company disclosed the breach in a filing with the U.S. Securities and Exchange Commission, the federal agency that public companies must inform when something material happens to their business. Nutex says the stolen files may include "private and/or confidential" information, but hasn't said whose.

What actually happened?

Someone got into Nutex's servers and took data. That's what the company has confirmed so far.

In the filing, Nutex says its investigation shows that "certain information maintained on the Company's servers was accessed and exfiltrated by an unauthorized third party." Exfiltrated is the industry word for copied out to a system the attacker controls: think of it as a burglar photographing files rather than smashing the safe.

After spotting the intrusion, Nutex brought in outside incident-response and forensic specialists, activated its cyber response plan, contained what it could, and told law enforcement.

Who is Nutex Health, and how big is this?

Nutex Health runs 28 hospitals and clinics across 12 states, including Bayou City ER & Hospital in Texas and Green Bay ER & Hospital in Wisconsin. The company reported annual revenue of $875 million in 2025, carries a market value of about $1.28 billion, and trades as NUTX on the Nasdaq Capital Market.

That last point is why the SEC filing exists: listed companies in the United States have to tell shareholders promptly when a cyber incident could matter to the business.

Detail Figure
Facilities 28 across 12 states
2025 revenue $875 million
Market cap $1.28 billion
Ticker NUTX (Nasdaq)
Disclosure date 24 August

Should patients and staff be worried?

Honest answer: nobody knows yet, including Nutex. The company says it's still working out whether patient records, employee files, credentialed-provider details, business and financial data, or intellectual property were caught up in the theft.

Hospitals hold some of the most sensitive personal data going: medical histories, insurance details, Social Security numbers. If any of that surfaces, U.S. Law requires Nutex to notify affected people directly. This is the fifth healthcare breach we've covered in the past 30 days, following the CareCloud incident on 19 August, where the full patient count took months to reach regulators.

Anyone treated at a Nutex facility, or who worked for one, should watch bank statements and insurance paperwork, and be wary of calls or emails referencing their care. That's the classic follow-on pattern after a healthcare breach.

Who did it?

Unclear. Nutex hasn't named a suspect, and as BleepingComputer reported, no ransomware or extortion group has posted Nutex on a leak site.

That could mean a few things. The attackers might still be negotiating quietly, or they could be a data-theft crew that never surfaces publicly. Nutex may also have caught them before they got everything they wanted. We'll update as more surfaces.

One note on the SEC angle. The filing is careful to say that as of 24 August the company doesn't believe the incident will materially affect its business or financial results. Nutex is telling investors the lights are still on. Whether that holds depends entirely on what turns out to have been in those files.

© 2026 Threat Vectr