Overview
Nutex Health, Inc. (Nasdaq: NUTX), a for-profit healthcare company operating 28 emergency room and hospital facilities across 12 U.S. states — including Bayou City ER & Hospital in Texas and Green Bay ER & Hospital in Wisconsin — has disclosed a cybersecurity incident in a Form 8-K filed with the SEC on August 24, 2026. The company reported $875 million in 2025 revenue and carries a market capitalization of roughly $1.28 billion.
According to the filing, Nutex Health "recently learned of unauthorized activity involving data stored on its computer network." The company engaged an independent third-party cybersecurity response team and forensic experts, activated its incident response plan, implemented containment measures, and notified law enforcement.
What Was Disclosed
| Detail | Status |
|---|---|
| Access & exfiltration | Confirmed — an unauthorized third party accessed and exfiltrated data from company servers |
| Data types under review | Patient, employee, credentialed provider, confidential business/financial information, and intellectual property |
| Scope of impact | Still being assessed — the company has not yet confirmed exactly which categories or how many individuals are affected |
| Business/financial systems impact | None identified to date |
| Threat actor claim | None identified publicly as of this writing |
Nutex Health stated it does not currently believe the incident is reasonably likely to have a material impact on its business strategy, operations, financial condition, or results of operations — standard forward-looking language required in SEC disclosures, though the company cautioned its investigation is ongoing and findings could change.
Why This Matters
Nutex operates emergency rooms and hospital facilities, meaning any confirmed exposure would likely fall under HIPAA and could involve protected health information (PHI) — one of the highest-value and most tightly regulated categories of personal data. Emergency medicine providers hold a particularly sensitive mix of records: treatment histories, insurance and billing details, and identifiers collected under time pressure during acute care, often with less opportunity for patients to control what information is captured.
As a publicly traded company, Nutex's SEC 8-K disclosure obligation (under the SEC's 2023 cybersecurity disclosure rules) requires reporting incidents determined to be material — or, as here, proactively disclosing before that determination is finalized. The filing is a snapshot of an active investigation, not a final accounting.
What Happens Next
The company says it "continues to evaluate applicable regulatory and legal notification requirements" and intends to notify affected patients and other individuals directly once its investigation identifies who was impacted. Under HIPAA's Breach Notification Rule, covered entities must generally notify affected individuals within 60 days of discovering a breach involving unsecured PHI — a clock that starts once Nutex's investigation confirms scope.
Plaintiffs' attorneys have already begun soliciting potentially affected individuals for a prospective class-action lawsuit, a now-routine step following healthcare sector breach disclosures.
What Affected Patients Should Do
Until Nutex issues formal notifications, individuals who have received care at a Nutex-operated facility (including Bayou City ER & Hospital or Green Bay ER & Hospital) should take proactive precautions:
- Monitor Explanation of Benefits (EOB) statements from your insurer for services you did not receive — a common indicator of medical identity theft.
- Review credit reports at AnnualCreditReport.com and consider a credit freeze if financial data exposure is later confirmed.
- Watch for phishing referencing Nutex, Bayou City ER, or Green Bay ER — breach data is frequently used to craft convincing follow-up scams.
- Retain records of any care received, in case they're needed to substantiate a future claim related to this incident.
Sources
- BleepingComputer — Hospital operator Nutex Health says data stolen in cyberattack
- SEC — Nutex Health Inc. Form 8-K (filed 2026-08-24)
- ClassAction.org — Nutex Health Data Breach Reported; Attorneys Investigating