Nutex Health, a for-profit healthcare company that operates 28 facilities across 12 states, is investigating a data breach in which an unauthorized third party stole information from its servers. The company disclosed the cyberattack in a filing with the U.S. Securities and Exchange Commission (SEC), stating that the exfiltrated data includes details that may be private or confidential. Based on preliminary findings from its ongoing investigation, Nutex said it believes certain information maintained on its servers was accessed and taken, including some data that may be private or confidential.

The company operates facilities including the Bayou City ER & Hospital in Texas and the Green Bay ER & Hospital in Wisconsin. Nutex had annual revenue of $875 million in 2025 and a market capitalization of $1.28 billion, and it trades publicly as NUTX on the Nasdaq Capital Market. The breach could affect patients, employees, or business partners, though Nutex has not yet determined the specific type of data compromised.

After detecting the intrusion, Nutex hired external incident-response and forensic specialists and activated its cybersecurity response plan. The company also implemented containment measures and notified law enforcement. Nutex continues to assess whether and to what extent patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other data may have been accessed, acquired, or exfiltrated.

The SEC filing notes that the company is still evaluating the potential impact of the unauthorized activity, including any possible disclosure of private or confidential information by the third party. As of August 24, Nutex said it found no material impact on its operations or financial reporting systems. The company currently does not believe the incident will materially affect its business strategy, operations, financial condition, or results.

BleepingComputer, which first reported the incident, could not find any threat actor claiming responsibility for the attack on Nutex. The publication also contacted Nutex for comment but had not received a response as of the time of its report. The incident comes amid broader warnings from the Health-ISAC about rising ShinyHunters data theft attacks on healthcare organizations.

The breach highlights ongoing cybersecurity risks for U.S. healthcare providers, which frequently handle sensitive patient and financial data. Nutex’s disclosure to the SEC is a standard regulatory step for publicly traded companies facing material cyber incidents. The company’s investigation remains ongoing, and further details about the scope of the stolen data have not yet been released.

More cybersecurity news from TechManNews.