STOCK TITAN

Nutex Health (NUTX) cyberattack exposes confidential data, threat to leak looms

(Moderate)
(Neutral)
Form Type
8-K

Rhea-AI Filing Summary

Nutex Health Inc. (NUTX) reports further details on a previously disclosed cybersecurity incident involving unauthorized activity on its computer network. An investigation, supported by an independent cybersecurity response team and forensic experts, indicates that an unauthorized third party accessed and exfiltrated data from Nutex servers, including patient and employee, credentialed provider, business and financial information that is private and/or confidential. The third party has threatened to post this information externally.

To date, Nutex states it has not identified any material impact on business operations or financial reporting systems. The company is continuing to assess the scope of data involved, potential impacts, and required regulatory and legal notifications, including notifications to impacted patients. A purported class action, Haley v. Nutex Health, Inc., has been filed in federal court in Texas in connection with the incident, and Nutex states it is currently unable to predict the outcome or the overall impact of the incident or related litigation on its business, financial condition, results of operations, or stock price.

Positive

  • None.

Negative

  • None.

Filing Explained

A August 27, 2026 complaint seeks to represent people whose personal or protected health information was allegedly accessed, asserting negligence, contract and unjust-enrichment claims and requesting damages, court-ordered relief, credit monitoring, identity-theft insurance, and legal fees.

Item 1.05 Material Cybersecurity Incidents Business
A cybersecurity incident that the company has determined to be material to investors.
Item 8.01 Other Events Other
Voluntary disclosure of events the company deems important to shareholders but not covered by other items.
Prior Form 8-K SEC filing date August 24, 2026 Date the earlier report on the cybersecurity incident was filed
Current report date August 31, 2026 Date Nutex Health signed the current report updating on the incident
Case number 4:26-cv-07197 Case number for Haley v. Nutex Health, Inc. in federal court
Material Cybersecurity Incidents technical
"Item 1.05 Material Cybersecurity Incidents."
exfiltrated technical
"information maintained on the Company’s servers was accessed and exfiltrated"
personally identifiable information regulatory
"whose personally identifiable information and/or protected health information was allegedly"
Personally identifiable information (PII) is any data that can directly or indirectly identify a single person — for example: full name, home address, national ID numbers, phone or email, financial account details, or unique biometric data. Investors care because mishandling or loss of PII can trigger regulatory fines, costly cleanup and lost customer trust; think of a data breach like losing the keys to many customers’ homes, which can hurt a company’s finances and stock value.
protected health information regulatory
"personally identifiable information and/or protected health information was allegedly accessed"
Protected health information is any personal medical or health-related data that can identify an individual—examples include diagnoses, treatment records, test results, insurance details, or an address when tied to health information. It matters to investors because organizations that collect, store or share this data face strict privacy laws, high breach and liability risk, and potential fines or reputational damage, making PHI a valuable but legally sensitive asset.
purported class action complaint regulatory
"Following the filing of the Prior 8-K, a purported class action complaint"

FAQ

What cybersecurity incident did Nutex Health Inc. (NUTX) disclose?

Nutex Health reported unauthorized activity on its computer network, where a third party accessed and exfiltrated patient, employee, credentialed provider, business and financial data that is private and/or confidential and has threatened to post the information externally.

Has the Nutex Health (NUTX) cyber incident affected operations or financial reporting?

Nutex Health states that, as of this report, it has not identified any material impact on its business operations or financial reporting systems from the cybersecurity incident, while its investigation and assessments remain ongoing.

What claims are asserted in the Haley v. Nutex Health, Inc. case against NUTX?

The complaint asserts claims including negligence, negligence per se, breach of third-party beneficiary contract, and unjust enrichment, and seeks compensatory and consequential damages, injunctive relief, credit monitoring, identity theft insurance, and attorneys’ fees and costs.

Is Nutex Health (NUTX) able to estimate the impact of the cyber incident and lawsuit?

Nutex Health states it is currently unable to predict the outcome of the litigation or estimate the potential impact of the incident on its business strategy, operations, financial condition, results of operations, or trading price of its common stock.

How is Nutex Health (NUTX) responding to the cybersecurity incident?

Nutex Health has engaged an independent cybersecurity response team and forensic experts, activated a cybersecurity response plan, implemented containment measures, notified law enforcement, and is evaluating regulatory and legal notification requirements, including notifications to impacted patients.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google
Learn about SEC filing dates
0001479681FALSE00014796812026-08-312026-08-31

UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549
 
FORM 8-K
 
CURRENT REPORT
Pursuant to Section 13 OR 15(d) of The Securities Exchange Act of 1934
  
Date of Report (Date of earliest event reported): August 31, 2026
  
NUTEX HEALTH INC.
(Exact name of registrant as specified in its charter)
  
Delaware 
001-41346
11-3363609 
(State or Other Jurisdiction 
of Incorporation) 
(Commission File Number) 
(I.R.S. Employer 
Identification No.) 
  
1776 Yorktown Street, Suite 700, Houston, Texas 77056
(Address of principal executive offices) (zip code)
  
(713) 660-0557
(Registrant’s telephone number, including area code) 
  
N/A 
(Former name or former address, if changed since last report) 
  
Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions: 
  
Written communication pursuant to Rule 425 under the Securities Act (17 CFR 230.425) 
Soliciting material pursuant to Rule 14a-12 under the Exchange Act (17 CFR 240.14a-12) 
Pre-commencement communication pursuant to Rule 14d-2(b) under the Exchange Act (17 CFR 240.14d-2(b)) 
Pre-commencement communication pursuant to Rule 13e-4(c) under the Exchange Act (17 CFR 240.13e-4(c)) 
  
Securities registered pursuant to Section 12(b) of the Act: 
  
Title of each class 
  
Trading Symbol(s) 
  
Name of each exchange on which registered 
Common Stock, $0.001 par value 
  
NUTX 
  
The NASDAQ Stock Market LLC 
  
Indicate by check mark whether the registrant is an emerging growth company as defined in Rule 405 of the Securities Act of 1933 (17 CFR §230.405) or Rule 12b-2 of the Securities Exchange Act of 1934 (17 CFR §240.12b-2). 
Emerging growth company  
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act.




Item 1.05 Material Cybersecurity Incidents.
As disclosed in Item 8.01 of a Current Report on Form 8-K filed with the Securities and Exchange Commission on August 24, 2026 (the “Prior 8-K”), Nutex Health Inc. (the “Company”) became aware of unauthorized activity involving data stored on its computer network. As disclosed in the Prior 8-K, the Company engaged an independent third-party cybersecurity response team and forensic experts, activated a cybersecurity response plan, implemented containment measures and notified law enforcement.
Based on the current status of the Company’s ongoing investigation, the Company believes that certain information maintained on the Company’s servers was accessed and exfiltrated by an unauthorized third party, including patient and employee, credentialed provider, business and financial information that is private and/or confidential. The third party has threatened to post such information externally. To date, the Company has not identified any material impact on its business operations or financial reporting systems.
The Company continues to assess whether, and to what extent, patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated and continues to evaluate the potential impact of the unauthorized activity on the Company, including any potential disclosure of private and/or confidential information by the third party. The Company continues to evaluate applicable regulatory and legal notification requirements, and the Company intends to make all required notifications based on its findings, including to impacted patients.
Following the filing of the Prior 8-K, a purported class action complaint captioned Haley v. Nutex Health, Inc., Case No. 4:26-cv-07197, was filed on August 27, 2026, against the Company in the United States District Court for the Southern District of Texas, Houston Division. The complaint was filed on behalf of a putative class of all individuals whose personally identifiable information and/or protected health information was allegedly accessed and/or acquired by an unauthorized party in connection with the incident. The complaint asserts claims for negligence, negligence per se, breach of third-party beneficiary contract, and unjust enrichment, and seeks, among other things, compensatory and consequential damages, injunctive relief, credit monitoring and identity theft insurance, and attorneys’ fees and costs.
At this stage, the Company is unable to predict the outcome of the litigation or estimate the potential impact of the incident on the Company’s business strategy, operations, financial condition, results of operations or the trading price of the Company’s common stock.
Forward-Looking Statements
This Current Report on Form 8-K contains “forward-looking statements” within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended. Such forward-looking statements are intended to be covered by the safe harbor provisions for forward-looking statements contained in the Private Securities Litigation Reform Act of 1995 and are included in this statement for purposes of complying with these safe harbor provisions. This document contains certain forward-looking statements with respect to current beliefs, understanding and expectations regarding the incident and its remediation and investigation. These forward-looking statements can be identified by the fact that they do not relate only to historical or current facts. Forward-looking statements often use words such as “estimate,” “project,” “predict,” “will,” “would,” “should,” “could,” “may,” “might,” “anticipate,” “plan,” “intend,” “believe,” “expect,” “aim,” “goal,” “target,” “objective,” “commit,” “advance,” “likely” or similar expressions that convey the prospective nature of events or outcomes.
These forward-looking statements reflect current beliefs, understanding and expectations regarding the incident and its remediation and investigation. Factors that could cause actual results to differ materially from those indicated in the forward-looking statements include, but are not limited to: litigation to which the Company has or may become subject in connection with the incident; the results of the Company’s ongoing investigation and analysis of the scope and details of the cybersecurity incident and the potential discovery of new and additional information related thereto; the Company’s expectations regarding its ability to contain and remediate the cybersecurity incident, including the success of containment and remediation activities to date; any unauthorized release of the Company’s data, including third-party data held by the Company, or the use of any such data for fraudulent purposes; potential loss or destruction of Company data or adverse impacts to the Company’s operations; the impact of the cybersecurity incident on the Company’s relationships with customers, employees, governmental regulators, and other stakeholders; diversion of management’s attention from the Company’s operations to addressing the cybersecurity incident; the legal, reputational, and financial risks resulting from the cybersecurity incident, including those that may arise from any potential regulatory inquiries; other reputational risk related to the cybersecurity incident; regulatory scrutiny of the cybersecurity incident; risks related to the availability of the Company’s insurance coverage for losses and costs associated with the cybersecurity incident; and remediation and other additional costs that may be incurred by the Company in connection with the investigation and




remediation of the incident. Readers are cautioned that these forward-looking statements are not guarantees of future events or outcomes and they should not be unduly relied on, as they are based on information available to the Company and on management’s current beliefs and expectations as of the date of this Current Report on Form 8-K and are therefore inherently uncertain and subject to risks, uncertainties, and assumptions that are difficult to predict, including those identified in our filings with the Securities and Exchange Commission, including the risk factors contained in our most recent Annual Report on Form 10-K and our Quarterly reports on Form 10-Q for the periods ended March 31, 2026 and June 30, 2026. We undertake no obligation to revise or update any forward-looking statements, including to reflect events or circumstances occurring after the date of the filing of this report, except to the extent required by law.




 
SIGNATURE
 
Pursuant to the requirements of the Securities Exchange Act of 1934, the Registrant has duly caused this report to be signed on its behalf by the undersigned, hereunto duly authorized.
 
Date: August 31, 2026
NUTEX HEALTH INC. 
  
  
  
By: 
/s/ Jon C. Bates 
  
  
Jon C. Bates 
Chief Financial Officer 
  
  
 


Filing Exhibits & Attachments

3 documents