Industry News

Nutex Health Confirms Stolen Data Published Online After Cybersecurity Incident

PRNewsWire · 11 Sept 2026
Key Takeaway SMBs should have an incident response and breach notification plan ready in advance, since even after containment, stolen data can resurface publicly and reopen legal and reputational risks.

Nutex Health, a Houston-based hospital and physician network operator with 28 facilities across 12 states, has provided an update on a cybersecurity event first disclosed to the SEC in late August 2026. The company says an unauthorized third party has now published on its own website data allegedly stolen from Nutex's network during the earlier breach.

Nutex has engaged third-party forensic and cybersecurity experts to download, process and analyse the leaked data to confirm its scope and authenticity, a process it expects to take several weeks given the volume involved. Law enforcement has been notified and containment measures remain in place. So far, the company says it has not identified any material impact on business operations or financial reporting systems, and its earlier materiality assessment is unchanged.

Nutex says it continues to evaluate its regulatory and legal notification obligations and intends to notify affected patients and employees once its review is complete. The company has indicated it will issue further updates, including any amendments to prior disclosures, as more information becomes available.

healthcare data breach incident response cybersecurity disclosure

Summarised by CISO AI from PRNewsWire. We link back to every original so you can read it yourself.