Texas-based healthcare provider Nutex Health has disclosed that an unauthorized actor stole sensitive information, including patient records, and has made threats to release it publicly. The company, which operates facilities across the United States, revealed the breach in an 8-K filing with the Securities and Exchange Commission on August 31. Nutex said it believes the compromised data includes patient and employee information, credentialed provider records, and business and financial details that are private or confidential.
The attacker initially gained unauthorized access to data stored on Nutex's computer network, which the company first detected and reported to the SEC on August 24. Nutex operates more than 27 facilities spread across 12 states, and the company reportedly treated nearly 100,000 patients during the first half of 2026. Following the initial disclosure, a class action complaint was filed on August 27 on behalf of individuals whose personally identifiable information or protected health information was accessed or obtained by an unauthorized party in connection with the incident. Legal firm Edelson Lechtzin LLP announced on September 1 that it's separately investigating the breach and offering to evaluate affected individuals' rights at no charge.
According to the filing, "the third party has threatened to post such information externally," and Nutex confirmed it will notify all impacted patients of the data breach. The company stated it's continuing to assess whether additional data was stolen during the attack and will monitor for any leaks online. To date, the provider hasn't identified any material impact on its business operations or financial reporting systems arising from the incident. However, Nutex stated it's unable to predict the outcome of the litigation or estimate the potential impact of the incident on the company's business strategy, operations, financial condition, results of operations, or the trading price of its common stock.
The Gentlemen ransomware gang has reportedly claimed responsibility for the attack, listing Nutex on its dark web portal. The ransomware-as-a-service operator first appeared in mid-2025, but its activity levels exploded in 2026 amid rapid affiliate growth. An analysis published by Sophos on September 1 highlighted the opportunistic nature of The Gentlemen affiliates, with victims spanning a wide variety of sectors. Healthcare is the group's second most commonly targeted industry, representing 9% of The Gentlemen victims, just behind manufacturing at 10%. Affiliates typically rely on exploiting vulnerabilities in firewalls and abusing VPN services to gain initial access into victim environments. On August 28, one of America's largest healthcare distributors, McKesson, confirmed it had suffered a data breach affecting customers within its Oncology & Multispecialty and Medical-Surgical business units, with reports suggesting as many as 284 million records may have been compromised and a $55 million ransom demand.
The Nutex breach underscores the escalating threat ransomware-as-a-service groups pose to healthcare providers, particularly as affiliates increasingly exploit common network vulnerabilities to gain entry. Organizations that delay fundamental security hardening around firewalls and VPN access may find themselves caught between litigation costs and operational disruption, even when immediate financial impact appears limited.

