Nutex Health Inc. — a Houston hospital operator traded as NUTX — told the SEC on August 31, 2026 that attackers accessed and copied private files from its servers. The Item 1.05 Form 8-K names patient, employee, credentialed provider, business, and financial information. The third party has threatened to post that data. Nutex said it has not seen a material hit to operations or financial reporting.
This is a confirmed material cybersecurity incident, not a rumor. Nutex did not name the crew. SecurityWeek and The Record reported that The Gentlemen (also tracked as Storm-2697) added the Houston company to a leak site and threatened a publication countdown. Treat the actor as a claim until Nutex attributes it.
This is not a duplicate of the ATF major-incident / Qilin claim (a federal standalone system, different victim). It is also not the same story as McKesson’s late-August service-degradation notice. Local Dallas Express ATF recaps and generic “AI ransomware” briefs in the same scan pile are other items.
Headquarters in the 8-K: 1776 Yorktown Street, Suite 700, Houston, Texas 77056. Nutex runs micro-hospitals and outpatient sites in 12 states, including Bayou City ER & Hospital in Humble.

Snapshot
| Field | Detail |
|---|---|
| Company | Nutex Health Inc. (NASDAQ: NUTX) |
| First 8-K | Item 8.01 — August 24, 2026 |
| Material filing | Item 1.05 — August 31, 2026 |
| Actor | The Gentlemen claimed; not named by Nutex |
| CourtListener | Haley v. Nutex Health, Inc. · 4:26-cv-07197 · S.D. Tex. · Aug 27, 2026 |
What Nutex told the SEC
The August 24 Item 8.01 said Nutex found unauthorized activity on its network, hired outside responders, contained systems, and notified law enforcement. It already believed some private files had been copied.
The August 31 upgrade to Item 1.05 is the material-incident box. Nutex now believes the copied set includes patient and employee, credentialed provider, business, and financial records. Scope is still under review, including whether intellectual property was taken. The company intends to notify impacted patients once the investigation supports it.
Do not treat a missing Texas OAG row yet as “no residents were affected.” The 8-K says notifications are still being evaluated.

The Gentlemen claim — and the Texas lawsuit
Nutex’s filing does not identify a ransomware brand. SecurityWeek (September 1) said The Gentlemen listed Nutex and threatened to leak alleged stolen data within nine days. The Record describes the crew as ransomware-as-a-service, with reporting that it grew out of a former Qilin affiliate and that forum posts are in Russian. That is background on the claim, not Nutex attribution.
After the first 8-K, a putative class action — Haley v. Nutex Health, Inc., 4:26-cv-07197 — was filed August 27, 2026 in the Southern District of Texas, Houston Division. CourtListener has the RECAP docket. The 8-K says the complaint alleges PII / PHI access and asserts negligence, negligence per se, third-party-beneficiary contract, and unjust enrichment. Nutex said it cannot predict the outcome.
What patients and staff should do
- Type nutexhealth.com or your own facility host (for Humble: bayoucityhospital.com). Do not use a “records restored / settlement portal” link from email or text.
- Watch for official patient notices from Nutex. Until then, treat “your Nutex file is online — pay to suppress” messages as unverified.
- Freeze credit and watch bank / insurance EOBs if you were treated at a Nutex site or work there.
- Employees and credentialed providers: reset work passwords on a host you typed; assume follow-on payroll and licensing phishing.
- Texas residents can use the Texas OAG breach portal once a filing appears. Nationwide: IC3.
MFA: YubiKey and Google Authenticator
A hardware key does not un-copy files that already left the network. It does cut a lot of the follow-on “verify your chart / W-2 / credential” phishing that follows a healthcare headline. Grades match our MFA directory.
| Grade | Meaning |
|---|---|
| Fail | Documented second factor is SMS, voice, or email OTP — or no public path |
| Pass | Self-serve Google Authenticator-style open TOTP |
| Strong | FIDO2 / YubiKey-class security key for sign-in |
| Platform | Grade | YubiKey | Authenticator |
|---|---|---|---|
| Nutex / Bayou City | Fail | No | No |
| Epic MyChart | Fail | Key only | Yes |
Nutex’s corporate and Humble hospital sites publish no patient-portal MFA help that names a YubiKey or Google Authenticator. We do not invent a central MyChart tenant. Epic’s two-step help still documents SMS/email OTP (Fail) even when an authenticator app is offered.
Directory: MFA support directory · Category → Healthcare.
Recommended MFA tools
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
We audited the official Nutex, Humble hospital, SEC filing, and researcher hosts on September 5, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not say how the servers were reached.
| Organization | Domain | Overall | vs 100% |
|---|---|---|---|
| U.S. SEC | sec.gov | 88% | −12 |
| Bayou City ER | bayoucityhospital.com | 50% | −50 |
| Nutex Health | nutexhealth.com | 46% | −54 |
| Sophos | sophos.com | 44% | −56 |
| Domain | Identity | Transport | Website |
|---|---|---|---|
| sec.gov | 90% | 45% | 98% |
| bayoucityhospital.com | 40% | 50% | 37% |
| nutexhealth.com | 30% | 50% | 37% |
| sophos.com | 25% | 50% | 37% |
Audit links: sec.gov · bayoucityhospital.com · nutexhealth.com · sophos.com
Nutex Identity 30% and Bayou City 40% mean spoofed “Humble records / NUTX notice” mail is easier to deliver than the overall scores suggest. sec.gov is the filing host, not the victim.

Website stack note
Passive website-tech probes on September 5, 2026:
| Domain | Stack signal |
|---|---|
| nutexhealth.com | WordPress (version hidden); GoDaddy TLS expires 2027-02-11 |
| bayoucityhospital.com | WordPress (version hidden); Google Trust TLS expires 2026-11-14 |
| sec.gov | Drupal (version hidden); DigiCert TLS expires 2027-03-02 |
| sophos.com | Next.js; Let’s Encrypt TLS expires 2026-11-17 |
Point-in-time only. A live marketing homepage is not a forensic finding on the copied servers.
Blacklist and lookalike domains
Email blacklist checks (public DoH, September 5, 2026): nutexhealth.com, bayoucityhospital.com, sec.gov, and sophos.com were clear on mail/domain lists we can query. A web/CDN IP on sec.gov showed an informational SPFBL note — not a mail-reputation hit.
DNS lookalike scans (BEC profile, registered signals only):
| Brand scanned | To review | Likely owned | BEC staging |
|---|---|---|---|
| nutexhealth.com | 2 | 0 | 0 |
| bayoucityhospital.com | 0 | 0 | 0 |
| sec.gov | 14 | 0 | 0 |
| sophos.com | 48 | 4 | 1 |
High-interest registered names (investigate; not proof this incident used them):
| Lookalike | Technique | Note |
|---|---|---|
| nutrexhealth.com | insertion | Live NS + A + MX |
| nutrxhealth.com | adjacent-key | Live NS + A + MX |
| sec.com | tld-swap | Not the .gov Commission |
| sophos-support.com | affix | Live NS + A + MX |
| sophios.com | insertion | BEC staging (NS + MX) |
Type nutexhealth.com and bayoucityhospital.com, not a one-letter swap. Continuous monitoring: Cybersquat Domain Monitoring.
Related coverage
- ATF major incident / Qilin claim (different victim; same-week scan noise)
- JPS Health Network outage
- PA AG MyChart phishing
- Healthcare AG breach tracker
- Texas OAG YTD dashboard
- MFA support directory
Run a free audit at audit.emailmenow.com or contact EmailMeNow for healthcare DMARC / MTA-STS and phishing response aimed at the 100% ideal.
Sources: Nutex Item 1.05 Form 8-K (Aug 31, 2026) · Item 8.01 Form 8-K (Aug 24, 2026) · SecurityWeek · The Record · HIPAA Journal · BleepingComputer (Aug 24 filing only) · Haley v. Nutex Health, Inc. (4:26-cv-07197). Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 5, 2026. Domain scores: audit.emailmenow.com only.