Houston-based hospital operator Nutex Health (NASDAQ: NUTX) has confirmed in an SEC filing that an unauthorized third party accessed and exfiltrated patient, employee, credentialed provider, business and financial information from its servers, and has threatened to publish it. The confirmation came in an August 31, 2026 Form 8-K filed under Item 1.05, the section reserved for material cybersecurity incidents, escalating an initial Item 8.01 disclosure made on August 24. The Gentlemen ransomware-as-a-service operation claimed the attack on Monday by adding Nutex to its leak site. No source has published a victim count or record volume, and Nutex says its investigation into scope is ongoing.
What Happened
The timeline across the reporting is consistent. On August 24, 2026, Nutex told the SEC it had recently detected unauthorized activity involving data stored on its computer network. Per BleepingComputer and SecurityWeek's initial coverage, the company activated its cybersecurity response plan, implemented containment measures, engaged an independent third-party incident response team and forensic experts, and notified law enforcement. At that point Nutex said only that "some information that may be private and/or confidential" had been exfiltrated, and stated it did not believe the intrusion had had, or was reasonably likely to have, a material impact on its business.
That posture changed a week later. The August 31 filing, reported by The Record, Infosecurity Magazine, HIPAA Journal, SecurityWeek and The Register, states that Nutex now believes "certain information maintained on the Company's servers was accessed and exfiltrated by an unauthorized third party, including patient and employee, credentialed provider, business and financial information that is private and/or confidential." The company added: "The third party has threatened to post such information externally."
Reclassifying the event under Item 1.05 is the substantive move here. Item 8.01 is a catch-all for other events; Item 1.05 is a determination of materiality to investors. Per the StockTitan summary of the filing, the 8-K carried both items. Nutex has not publicly named the attacker in any filing.
The Gentlemen claimed responsibility on Monday, August 31, by listing Nutex on its Tor leak site. The Register notes the gang offered no proof or detail to substantiate the claim, which is worth holding onto: leak-site listings are a pressure tactic, and the attribution rests on the crew's own claim rather than on anything Nutex or a forensic vendor has confirmed. SecurityWeek reports the listing came with a threat to publish within nine days.
Accounts differ on Nutex's footprint. The Register and BleepingComputer put it at 28 facilities across 12 states; HIPAA Journal and The Record say 27 micro-hospitals, specialty hospitals and outpatient departments across 12 states. The Record reports $427.2 million in first-half 2026 revenue; BleepingComputer cites $875 million in annual 2025 revenue and a $1.28 billion market cap.
What Was Taken
Nutex has named data categories, not volumes. Per the August 31 filing as quoted by multiple outlets, the exfiltrated set includes:
- Patient information, which in a hospital-operator context means protected health information
- Employee information
- Credentialed provider information, covering physicians and clinicians affiliated with the network rather than on payroll
- Confidential business information
- Financial information
The initial August 24 filing had also flagged intellectual property as a category still under assessment. The confirmed list in the later filing does not include it, and the company continues to evaluate whether other data was involved.
No source in this set provides a record count or an affected-individual figure, and none should be inferred. SecurityWeek's older piece notes only the general base rate that healthcare breaches often reach hundreds of thousands or millions of people, referencing unrelated incidents. Treat any circulating number as unsourced until Nutex files with HHS OCR or issues notification letters. Infosecurity Magazine reports Nutex has confirmed it will notify all impacted patients and will monitor for leaks online.
On business impact, Nutex maintains that to date it has not identified any material impact on business operations or financial reporting systems, which is a narrower claim than the materiality determination that triggered the Item 1.05 filing.
Why It Matters
Three things make this brief worth a defender's time beyond the usual healthcare breach cadence.
First, the legal clock started before the forensics finished. A putative class action was filed in federal court in Texas on August 27, three days after the initial disclosure and four days before Nutex confirmed what was taken. StockTitan's filing summary identifies it as Haley v. Nutex Health, Inc., asserting negligence, contract and unjust enrichment claims and seeking damages, credit monitoring, identity theft insurance and fees. That is a single OTHER-tier source for the case caption; the existence and August 27 date of the complaint are confirmed across The Record, Infosecurity and The Register. Nutex says it cannot predict the outcome or estimate the impact on its business or stock price.
Second, the credentialed provider data is the underrated exposure. Affiliated physicians who are not employees still have credentialing files containing licensure, DEA registration, malpractice history and personal identifiers. Those individuals are frequently outside the victim organization's notification workflows and outside its identity monitoring offers, and they are high-value targets for downstream fraud.
Third, The Gentlemen is a young operation moving fast. SecurityWeek reports the group, also tracked as Storm-2697, emerged in mid-2025 and has claimed more than 580 victims across over 75 countries; The Record dates the RaaS to September 2025 and cites experts describing it as the work of a disgruntled affiliate of another operation. Those origin accounts do not fully agree, and the 580-victim figure is a single-outlet claim carried by the group's own leak-site accounting, which historically inflates. Either way, the operation is running double extortion and treating healthcare as in scope.
The Attack Technique
Initial access is not established. Neither Nutex's filings nor any outlet in this set describes an intrusion vector, a vulnerability, a malware family, or dwell time. Nutex has not said whether systems were encrypted or whether a ransom demand was received; HIPAA Journal explicitly notes the absence of any ransom disclosure in the August 24 filing.
What can be stated is the extortion model. SecurityWeek describes The Gentlemen as running conventional double extortion, encrypting victim data and exfiltrating it as leverage. The observable pattern in this case is exfiltration-first pressure: data theft confirmed by the victim, a leak-site listing with a countdown, and no reported disruption to clinical or financial systems. That is consistent with either a theft-only operation or an encryption attempt that containment interrupted. The sources do not let you distinguish between the two.
Defenders should not build detections off assumed TTPs here. The useful signal for now is the actor name and the leak-site behavior, not a technical chain.
What Organizations Should Do
- Instrument for bulk egress, not just encryption. This incident was detected and disclosed as data movement off servers. Alert on anomalous outbound volume from file shares, EHR-adjacent databases and backup infrastructure, and set thresholds against per-system baselines rather than a global number.
- Pull credentialing and provider-relations systems into scope. Inventory where licensure, DEA and malpractice data lives, apply the same access controls and monitoring you apply to the EHR, and build a notification path for affiliated providers who are not on your HR roster.
- Pre-write the Item 1.05 decision process. Nutex escalated from Item 8.01 to Item 1.05 in seven days. Public companies should have legal, security and disclosure counsel aligned in advance on what evidence flips an incident from "other event" to "material," so the escalation is a documented judgment rather than an improvised one.
- Assume litigation lands before your forensics do. A class action arrived three days after first disclosure. Preserve logs, forensic images and vendor communications from hour one, and coordinate public statements with the understanding that each one becomes an exhibit.
- Rehearse the leak-site countdown scenario. A nine-day publication threat compresses decisions about patient notification, regulator contact and public messaging. Run the tabletop now, including who monitors the leak site and who authorizes what gets said when data actually posts.
- Segment and harden third-party and remote access paths into clinical networks. With no confirmed vector in this case, the defensible move is closing the categories that dominate healthcare intrusions: exposed remote access, unmanaged vendor connections, and flat networks that let a single foothold reach patient, employee and finance data stores alike.
Sources: The Gentlemen come calling as Nutex confirms sensitive data theft | Nutex Health Confirms Sensitive Data Stolen in August Cyberattack | Healthcare facilities operator Nutex says patient, employee data st... | Ransomware Gang Claims Nutex Health Data Breach - SecurityWeek | Hospital operator Nutex Health says data stolen in cyberattack | Nutex Health Says Patient Data Stolen, Hackers Threaten Leak - Info... | Sensitive Information Exposed in Nutex Health Data Breach - Securit... | Nutex Health hit by data theft in cyber breach NUTX 8-K Filing