Nutex Health, the for-profit operator of 28 hospitals and emergency rooms across 12 states, disclosed in an SEC filing that an unauthorized party accessed and exfiltrated data from company servers.
The filing, dated August 24, says the stolen information may be private and confidential, and that the company is still assessing whether patient, employee, provider, or business records were taken. Incident response and forensic specialists have been brought in, containment measures activated, and law enforcement notified, Nutex said in its filing. It found no material impact on operations or financial reporting as of August 24.
The Houston-based operator, listed on the Nasdaq as NUTX, booked roughly $875M in revenue last year and runs Bayou City ER & Hospital in Texas along with Green Bay ER & Hospital in Wisconsin. Based on what it knows today, Nutex does not expect the intrusion to hit its business, financial standing, or results in a material way.
No threat actor had claimed responsibility for the intrusion as of August 25. The disclosure adds another mid-size hospital operator to a summer of healthcare attacks, and downstream vendors and partner facilities should watch for any follow-on notifications.