NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Nutex Health Confirms Sensitive Data Stolen in August Cyberattack

Nutex Health, a Houston, Texas-based healthcare management and operations company that delivers care through 27 micro-hospitals, specialty hospitals, and outpatient departments in 12 U.S. states, has disclosed a cyberattack involving the exfiltration of data from some of its servers. Nutex is currently investigating the incident to determine the extent of data theft, including whether provider, employee, or patient data were exposed or stolen.

The incident was disclosed in an August 24, 2026, Item 8.01 Form 8-K filing with the U.S. Securities and Exchange Commission (SEC). Nutex explained that it recently learned of unauthorized activity related to data stored on its computer network. The company activated its incident response plan, implemented containment measures, and engaged an independent third-party cybersecurity response team and forensics experts to assist with the investigation and determine the extent to which data was exposed or stolen.

Per that filing, Nutex said the incident is still being assessed, and it has yet to determine whether private and confidential data was compromised in the incident. At the time, Nutex said it did not believe that the unauthorized access has, had, or is reasonably likely to have a material impact on the company’s business strategy, operations, financial condition or results of operations. Nutex did not disclose the name of the threat group behind the attack or whether it received a ransom demand, but it was aware that private and/or confidential information may be disclosed by the threat actor. At the time, no cybercriminal group had claimed responsibility for the attack.

Then, on August 31, 2026, Nutex filed an Item 1.05 Form 8-K filing with the SEC confirming that this is a material cybersecurity incident. The August 31, 2026, filing states that, “Based on the current status of the Company’s ongoing investigation, the Company believes that certain information maintained on the Company’s servers was accessed and exfiltrated by an unauthorized third party, including patient and employee, credentialed provider, business, and financial information that is private and/or confidential.”

Nutex also confirmed that the threat actor has threatened to publish the stolen data; however, the company has not yet identified any material impact on its business operations or financial reporting systems. Nutex is continuing to assess the impacted data and the extent to which patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated.

The threat group behind the attack on Nutex appears to be The Gentlemen, a ransomware-as-a-service (RaaS) operation that first appeared in mid-2025 and significantly ramped up attacks in 2026. While the group’s attacks appear to be opportunistic, the healthcare sector accounts for around 9% of its attacks. The Gentlemen engages in double extortion tactics, exfiltrating sensitive data and demanding a ransom to decrypt files and prevent the release of stolen data.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist