CiberLATAMbywhalemate

Nutex Health confirms publication of stolen data

Nutex Health told the SEC a third party posted data allegedly taken from its network and said it found no material business or reporting impact.

Whalemate Labs · AI-assisted researchPublished:2 min read

Nutex Health told the SEC that an unauthorized third party posted on its own website data allegedly taken from the company’s network. The company said it has not identified any material impact on operations or financial reporting systems and kept the same assessment it disclosed on August 31, 2026.

Nutex Health told the SEC that an unauthorized third party published on its own website data allegedly taken from the company’s computer network. In its filing dated September 10, 2026, the company said it has not identified any material impact on its business operations or financial reporting systems.

What did Nutex Health say about the incident?

Nutex Health repeated the same materiality assessment it included in its Form 8-K filed on August 31, 2026. In that follow-up SEC update, the company said the online publication of data tied to the incident has not, so far, materially affected its business or financial reporting.

Financial and market coverage says Nutex Health operates 28 hospital facilities across 12 U.S. states. That places the case within a multi-state healthcare operator, although it does not change the company’s view of the impact seen to date.

What is known about the theft and the investigation?

An independent security alert aggregator described the case as a data breach in which an unauthorized third party exfiltrated information from the company’s servers. The same monitoring source said Nutex Health is still investigating the scope of the data theft.

The public timeline of the incident began with an initial disclosure on August 24, 2026, and later led to the online publication of allegedly stolen data, according to available coverage. Western Networks added that it is a U.S. healthcare and hospital operator, and that the investigation remains open.

What context does the Storm attribution add?

A ransomware leak-site monitor reported that the Storm group added WindRose Health Network to lists of healthcare victims in Indiana. That provides additional context for the attribution mentioned in the original coverage, although the entry does not yet detail the volume of exposed data or publicly confirm the entity’s response.

At the same time, the WindRose reference adds to a recent run of incidents affecting U.S. healthcare providers, including Nutex Health, in an environment where attackers look to exploit both data exposure and the operational strain on hospitals and care networks.

What precedent does this type of case leave?

The mention of Change Healthcare serves as a high-impact precedent in the U.S. healthcare system, where outages and data leaks can escalate quickly. In this case, however, Nutex Health says it has not detected any material effect on its business or financial statements so far.

Sources

View all