Back to news
Cybersecurity Alert
September 1, 2026 by EmailMeNow IT Consulting

Nutex Health Confirms Patient and Employee Data Stolen — The Gentlemen Claimed It

Houston-based Nutex (NUTX) filed Item 1.05 after attackers stole patient, employee, provider, and financial files. The Gentlemen claimed the listing. Audits (ideal 100%): sec.gov 88%, bayoucityhospital.com 50%, nutexhealth.com 46%, sophos.com 44%. No public YubiKey or authenticator path.

Source: Nutex Health · SEC · SecurityWeek · The Record

NewsHealthcareTexasHoustonData BreachRansomwareMFAYubiKeyAuthenticator AppsCybersecurity
Hospital lobby at dusk with a darkened records monitor showing a missing-files warning

Nutex Health Inc. — a Houston hospital operator traded as NUTX — told the SEC on August 31, 2026 that attackers accessed and copied private files from its servers. The Item 1.05 Form 8-K names patient, employee, credentialed provider, business, and financial information. The third party has threatened to post that data. Nutex said it has not seen a material hit to operations or financial reporting.

This is a confirmed material cybersecurity incident, not a rumor. Nutex did not name the crew. SecurityWeek and The Record reported that The Gentlemen (also tracked as Storm-2697) added the Houston company to a leak site and threatened a publication countdown. Treat the actor as a claim until Nutex attributes it.

This is not a duplicate of the ATF major-incident / Qilin claim (a federal standalone system, different victim). It is also not the same story as McKesson’s late-August service-degradation notice. Local Dallas Express ATF recaps and generic “AI ransomware” briefs in the same scan pile are other items.

Headquarters in the 8-K: 1776 Yorktown Street, Suite 700, Houston, Texas 77056. Nutex runs micro-hospitals and outpatient sites in 12 states, including Bayou City ER & Hospital in Humble.

Hospital lobby at dusk with a darkened records monitor showing a missing-files warning

Snapshot

FieldDetail
CompanyNutex Health Inc. (NASDAQ: NUTX)
First 8-KItem 8.01August 24, 2026
Material filingItem 1.05August 31, 2026
ActorThe Gentlemen claimed; not named by Nutex
CourtListenerHaley v. Nutex Health, Inc. · 4:26-cv-07197 · S.D. Tex. · Aug 27, 2026

What Nutex told the SEC

The August 24 Item 8.01 said Nutex found unauthorized activity on its network, hired outside responders, contained systems, and notified law enforcement. It already believed some private files had been copied.

The August 31 upgrade to Item 1.05 is the material-incident box. Nutex now believes the copied set includes patient and employee, credentialed provider, business, and financial records. Scope is still under review, including whether intellectual property was taken. The company intends to notify impacted patients once the investigation supports it.

Do not treat a missing Texas OAG row yet as “no residents were affected.” The 8-K says notifications are still being evaluated.

Regulatory filing packet beside a leak-site name card stamped claimed, not proven

The Gentlemen claim — and the Texas lawsuit

Nutex’s filing does not identify a ransomware brand. SecurityWeek (September 1) said The Gentlemen listed Nutex and threatened to leak alleged stolen data within nine days. The Record describes the crew as ransomware-as-a-service, with reporting that it grew out of a former Qilin affiliate and that forum posts are in Russian. That is background on the claim, not Nutex attribution.

After the first 8-K, a putative class action — Haley v. Nutex Health, Inc., 4:26-cv-07197 — was filed August 27, 2026 in the Southern District of Texas, Houston Division. CourtListener has the RECAP docket. The 8-K says the complaint alleges PII / PHI access and asserts negligence, negligence per se, third-party-beneficiary contract, and unjust enrichment. Nutex said it cannot predict the outcome.

What patients and staff should do

  1. Type nutexhealth.com or your own facility host (for Humble: bayoucityhospital.com). Do not use a “records restored / settlement portal” link from email or text.
  2. Watch for official patient notices from Nutex. Until then, treat “your Nutex file is online — pay to suppress” messages as unverified.
  3. Freeze credit and watch bank / insurance EOBs if you were treated at a Nutex site or work there.
  4. Employees and credentialed providers: reset work passwords on a host you typed; assume follow-on payroll and licensing phishing.
  5. Texas residents can use the Texas OAG breach portal once a filing appears. Nationwide: IC3.

MFA: YubiKey and Google Authenticator

A hardware key does not un-copy files that already left the network. It does cut a lot of the follow-on “verify your chart / W-2 / credential” phishing that follows a healthcare headline. Grades match our MFA directory.

GradeMeaning
FailDocumented second factor is SMS, voice, or email OTP — or no public path
PassSelf-serve Google Authenticator-style open TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
PlatformGradeYubiKeyAuthenticator
Nutex / Bayou CityFailNoNo
Epic MyChartFailKey onlyYes

Nutex’s corporate and Humble hospital sites publish no patient-portal MFA help that names a YubiKey or Google Authenticator. We do not invent a central MyChart tenant. Epic’s two-step help still documents SMS/email OTP (Fail) even when an authenticator app is offered.

Directory: MFA support directory · Category → Healthcare.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key and phone authenticator beside a hospital billing envelope

Independent cybersecurity audits

We audited the official Nutex, Humble hospital, SEC filing, and researcher hosts on September 5, 2026. 100% is the idealnone reach it. These scores are public email / transport / website posture. They do not say how the servers were reached.

OrganizationDomainOverallvs 100%
U.S. SECsec.gov88%−12
Bayou City ERbayoucityhospital.com50%−50
Nutex Healthnutexhealth.com46%−54
Sophossophos.com44%−56
DomainIdentityTransportWebsite
sec.gov90%45%98%
bayoucityhospital.com40%50%37%
nutexhealth.com30%50%37%
sophos.com25%50%37%

Audit links: sec.gov · bayoucityhospital.com · nutexhealth.com · sophos.com

Nutex Identity 30% and Bayou City 40% mean spoofed “Humble records / NUTX notice” mail is easier to deliver than the overall scores suggest. sec.gov is the filing host, not the victim.

Domain audit scoreboard versus the 100 percent ideal

Website stack note

Passive website-tech probes on September 5, 2026:

DomainStack signal
nutexhealth.comWordPress (version hidden); GoDaddy TLS expires 2027-02-11
bayoucityhospital.comWordPress (version hidden); Google Trust TLS expires 2026-11-14
sec.govDrupal (version hidden); DigiCert TLS expires 2027-03-02
sophos.comNext.js; Let’s Encrypt TLS expires 2026-11-17

Point-in-time only. A live marketing homepage is not a forensic finding on the copied servers.

Blacklist and lookalike domains

Email blacklist checks (public DoH, September 5, 2026): nutexhealth.com, bayoucityhospital.com, sec.gov, and sophos.com were clear on mail/domain lists we can query. A web/CDN IP on sec.gov showed an informational SPFBL note — not a mail-reputation hit.

DNS lookalike scans (BEC profile, registered signals only):

Brand scannedTo reviewLikely ownedBEC staging
nutexhealth.com200
bayoucityhospital.com000
sec.gov1400
sophos.com4841

High-interest registered names (investigate; not proof this incident used them):

LookalikeTechniqueNote
nutrexhealth.cominsertionLive NS + A + MX
nutrxhealth.comadjacent-keyLive NS + A + MX
sec.comtld-swapNot the .gov Commission
sophos-support.comaffixLive NS + A + MX
sophios.cominsertionBEC staging (NS + MX)

Type nutexhealth.com and bayoucityhospital.com, not a one-letter swap. Continuous monitoring: Cybersquat Domain Monitoring.


Run a free audit at audit.emailmenow.com or contact EmailMeNow for healthcare DMARC / MTA-STS and phishing response aimed at the 100% ideal.


Sources: Nutex Item 1.05 Form 8-K (Aug 31, 2026) · Item 8.01 Form 8-K (Aug 24, 2026) · SecurityWeek · The Record · HIPAA Journal · BleepingComputer (Aug 24 filing only) · Haley v. Nutex Health, Inc. (4:26-cv-07197). Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 5, 2026. Domain scores: audit.emailmenow.com only.