Zero Day Room
Live
Threats

Nutex Health breach exposes patient data

US healthcare provider Nutex Health disclosed a data breach where patient and employee information was stolen, with a ransomware group claiming

US healthcare provider Nutex Health disclosed a data breach where patient and employee information was stolen, with a...

Nutex Health has disclosed that an unauthorized third party accessed and stole sensitive patient and employee data, threatening to publish it online. The Texas-based healthcare provider filed the notification with the US Securities and Exchange Commission on August 31.

The company stated that the stolen information includes patient and employee data, credentialed provider details, and private business and financial records. Nutex said it is continuing to assess the full scope of the stolen data and will monitor for any online leaks. It has pledged to notify all impacted patients.

Nutex first informed the SEC of unauthorized activity on its network on August 24. The firm has not identified any material impact on its business operations or financial reporting systems from the incident so far.

Legal action follows breach

Following the initial disclosure, a class action complaint was filed on August 27. The lawsuit represents individuals whose personally identifiable information or protected health information was accessed or acquired in the breach.

Nutex stated it is unable to predict the outcome of this litigation or estimate the potential impact on its business. Separately, legal firm Edelson Lechtzin LLP announced on September 1 that it is investigating the breach and offering to evaluate affected individuals' rights at no cost.

Ransomware group claims responsibility

The Gentlemen ransomware gang has reportedly claimed responsibility for the attack, listing Nutex Health on its dark web portal. This ransomware-as-a-service operator was first observed in mid-2025 and saw rapid affiliate growth in 2026.

An analysis by Sophos published on September 1 highlighted the opportunistic nature of The Gentlemen affiliates. The group targets a wide variety of sectors, with healthcare being its second most commonly targeted industry.

SectorPercentage of Victims
Manufacturing10%
Healthcare9%

Affiliates typically gain initial access by exploiting vulnerabilities in firewalls and abusing VPN services. The group's claim adds Nutex to a growing list of healthcare sector victims.

Broader healthcare targeting

The incident is part of a wider trend of attacks on healthcare organizations. On August 28, major healthcare distributor McKesson confirmed a data breach affecting customers within its Oncology & Multispecialty and Medical-Surgical business units.

Reports suggest as many as 284 million records may have been compromised in the McKesson breach, with the company facing a $55 million ransom demand. Ransomware group ShinyHunters posted an entry for McKesson on their leak site, claiming to have compromised hundreds of millions of records.

Nutex Health owns and operates over 27 facilities across 12 US states. The company reportedly served nearly 100,000 patients during the first six months of 2026.

Topics

#health

Related coverage

More from Threats