Nutex Health, a leading hospital operator with facilities across 12 states in the US, has revealed that it’s been hit by a cyberattack that resulted in sensitive data being stolen from its servers. The incident, which was disclosed in a filing with the Securities and Exchange Commission (SEC), is still under investigation, but initial findings suggest that unauthorized third-party access led to the theft of confidential information.
Nutex Health operates 28 facilities across Texas, Wisconsin, and 10 other states, providing emergency room and hospital services. The company’s annual revenue reached $875 million in 2025, with a market capitalization of $1.28 billion. Its publicly traded stock (NUTX on the Nasdaq Capital Market) has yet to be affected by the incident, with no material impact reported on its operations or financial reporting systems.
The attack, which is still being investigated, was detected after Nutex Health hired external experts and implemented containment measures. Law enforcement has been notified, but the company has not disclosed the type of data that may have been compromised, leaving patients, employees, business partners, and even the company’s intellectual property at risk. The SEC filing suggests that patient, employee, and confidential business information could be affected, but the extent of the breach is still unknown.
In cases like these, it’s common for attackers to gain access using valid credentials, often obtained through phishing or other social engineering tactics. Once inside, they can move freely within a network, potentially accessing sensitive data without being blocked by traditional security measures. This highlights the importance of robust authentication and access control mechanisms, as well as ongoing employee education and awareness programs.
While it’s unclear who is responsible for the attack on Nutex Health, similar incidents have been reported in the healthcare sector recently, including breaches at CareCloud, Unlimited Technology Systems, Amgen, and MCBS. These attacks often involve data theft, with sensitive information being sold or traded online. The rise of these incidents underscores the need for enhanced cybersecurity measures within the healthcare industry.
As Nutex Health continues to assess the impact of this incident, it’s essential for patients, employees, and business partners to remain vigilant. This includes monitoring financial accounts for suspicious activity, reporting any anomalies to the company, and taking steps to protect personal data in the event of a breach. For its part, Nutex Health should prioritize transparency and communicate openly with affected parties about the type of data that may have been compromised and what steps are being taken to prevent similar incidents in the future.
For individuals and organizations alike, this incident serves as a reminder of the importance of robust cybersecurity measures, including regular software updates, employee education, and ongoing threat monitoring. By taking these precautions, we can better protect ourselves against the growing threats in the cyber landscape.
Source: Bleeping Computer — 2026-08-25