Nutex Health Reports Data Breach, Sensitive Information Potentially Exposed
Healthcare services company Nutex Health has disclosed a data breach following unauthorized access and exfiltration of sensitive information from its network.

Nutex Health Inc., a prominent healthcare services and operations company, has reported a significant data breach after detecting unauthorized access to its network. The incident, detailed in a recent SEC filing, involved the exfiltration of files stored on some of the company's servers, raising concerns about the potential exposure of sensitive information.
The company, which operates micro-hospitals, specialty hospitals, and outpatient departments, is currently conducting an investigation to determine the full scope and nature of the compromised data. The investigation aims to ascertain whether information related to patients, employees, providers, business operations, financial data, and intellectual property was accessed or stolen by the attackers.
Despite the ongoing investigation, Nutex Health stated in its filing that it does not currently believe the breach will have a material impact on its business strategy, operations, financial condition, or results. However, the company acknowledged that the attacker may potentially leak the stolen information, a common tactic employed by cybercriminals following such incidents.
No specific cybercrime group has yet claimed responsibility for the attack. The healthcare sector remains a prime target for cyberattacks due to the highly sensitive and valuable nature of the data it holds. Breaches in this industry can have far-reaching consequences, impacting millions of individuals and leading to significant financial and reputational damage for the affected organizations.
This incident underscores the persistent threats faced by healthcare organizations in safeguarding patient and operational data. The complexity of healthcare systems and the increasing sophistication of threat actors necessitate continuous vigilance and robust cybersecurity measures. Nutex Health's disclosure highlights the critical importance of timely reporting and transparent communication following a security incident.
While the immediate financial impact may not be deemed material by Nutex Health, the potential exposure of sensitive data poses risks to individuals whose information may have been compromised. The company's commitment to investigating the full extent of the breach and implementing necessary security enhancements will be crucial in mitigating further risks and rebuilding trust with its stakeholders.
This updated disclosure from Nutex Health provides more detail on the incident, confirming that unauthorized actors accessed and exfiltrated data from its network. The company is actively investigating the full scope of the breach, which could involve patient, employee, or business records, and has engaged third-party forensic experts. While the initial access vector and specific impact are still under investigation, the incident underscores the persistent threats faced by the healthcare sector.
The ransomware group known as The Gentlemen (also identified as Storm-2697) has claimed responsibility for the breach at Nutex Health. This group, which emerged in mid-2025, operates as a ransomware-as-a-service (RaaS) and has reportedly victimized over 580 entities globally. The Gentlemen employs a double extortion tactic, involving both data encryption and exfiltration to pressure victims into paying ransoms.
Nutex Health has disclosed that the data breach, which occurred in August, involved the exfiltration of both patient and employee data. The company has filed with federal regulators regarding the incident, confirming an extortion attempt by threat actors following the data theft.
The Gentlemen ransomware gang has reportedly claimed responsibility for the attack on Nutex Health, listing the firm on its dark web portal. This group, observed since mid-2025, has seen its activity surge in 2026, with healthcare being its second most targeted industry. Affiliates commonly exploit firewall vulnerabilities and VPN services for initial access.