Breach taxonomy
Summary
Nutex Health disclosed that an unauthorized third party accessed and exfiltrated data from its servers, including patient, employee and credentialed-provider information along with confidential business and financial information. The attacker threatened to publish the data externally, and in a follow-up Item 8.01 filing on September 11, 2026 (accession 0001628280-26-061432) the company confirmed the data had been posted on the attacker's website. The company engaged third-party forensic experts, activated its cybersecurity response plan, implemented containment measures and notified law enforcement; it reported no material impact on business operations or financial reporting systems. A putative class action (Haley v. Nutex Health, Inc., S.D. Tex.) was filed on August 27, 2026, followed by several more. First disclosed under Item 8.01 on August 24, 2026 (accession 0001628280-26-058606).
Tagging rationale
ThreatUnknown
Filing refers only to 'an unauthorized third party' and does not identify an actor category -> UNKNOWN.
MethodsData Exfil
Filing states information maintained on company servers 'was accessed and exfiltrated by an unauthorized third party'; no encryption or outage is described -> DATA-EXFIL.
AssetsPersonal DataConfidential Biz
Filing states information 'accessed and exfiltrated' included 'patient and employee, credentialed provider, business and financial information that is private and/or confidential' -> PERSONAL-DATA plus CONFIDENTIAL-BIZ.
EffectsInfo Privacy LossCyber Extortion
Filing discloses exposure of private patient and employee information and that 'the third party has threatened to post such information externally', which it later did -> INFO-PRIVACY-LOSS plus CYBER-EXTORTION.
Business continuityNot Required
Filing states the company 'has not identified any material impact on its business operations or financial reporting systems', so no continuity procedures were needed -> Not Required.
Impact
Patient and employee PHI/PII across a multi-facility hospital operator was exfiltrated and subsequently published publicly, triggering multiple class actions, but with no operational disruption or disclosed financial figure -> score 3.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
Item 1.05 Material Cybersecurity Incidents. As disclosed in Item 8.01 of a Current Report on Form 8-K filed with the Securities and Exchange Commission on August 24, 2026 (the "Prior 8-K"), Nutex Health Inc. (the "Company") became aware of unauthorized activity involving data stored on its computer network. As disclosed in the Prior 8-K, the Company engaged an independent third-party cybersecurity response team and forensic experts, activated a cybersecurity response plan, implemented containment measures and notified law enforcement. Based on the current status of the Company's ongoing investigation, the Company believes that certain information maintained on the Company's servers was accessed and exfiltrated by an unauthorized third party, including patient and employee, credentialed provider, business and financial information that is private and/or confidential. The third party has threatened to post such information externally. To date, the Company has not identified any material impact on its business operations or financial reporting systems. The Company continues to assess whether, and to what extent, patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated and continues to evaluate the potential impact of the unauthorized activity on the Company, including any potential disclosure of private and/or confidential information by the third party. The Company continues to evaluate applicable regulatory and legal notification requirements, and the Company intends to make all required notifications based on its findings, including to impacted patients. Following the filing of the Prior 8-K, a purported class action complaint captioned Haley v. Nutex Health, Inc. , Case No. 4:26-cv-07197, was filed on August 27, 2026, against the Company in the United States District Court for the Southern District of Texas, Houston Division. The complaint was filed on behalf of a putative class of all individuals whose personally identifiable information and/or protected health information was allegedly accessed and/or acquired by an unauthorized party in connection with the incident. The complaint asserts claims for negligence, negligence per se, breach of third-party beneficiary contract, and unjust enrichment, and seeks, among other things, compensatory and consequential damages, injunctive relief, credit monitoring and identity theft insurance, and attorneys' fees and costs. At this stage, the Company is unable to predict the outcome of the litigation or estimate the potential impact of the incident on the Company's business strategy, operations, financial condition, results of operations or the trading price of the Company's common stock.