Nutex Health is investigating a cybersecurity incident after an unauthorized third party accessed its systems and exfiltrated information stored on company servers.
The healthcare provider disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC). According to preliminary findings from its investigation, some of the information taken during the intrusion may be private or confidential.
The company has not yet established exactly what information was compromised. Investigators are examining whether the stolen material includes patient or employee data, information belonging to credentialed healthcare providers, confidential financial and business records, intellectual property, or other sensitive information.
Nutex has also not disclosed how the attackers gained access to its environment or when the unauthorized activity began.
After discovering the intrusion, the company activated its cybersecurity incident response procedures and brought in external forensic and incident-response specialists. Nutex also implemented measures intended to contain the incident and notified law enforcement.
The investigation remains underway as the company works to determine the full scope of the unauthorized access and whether the stolen information has subsequently been disclosed by those responsible.
Nutex Health operates healthcare facilities across the United States. According to the company, its network includes 28 facilities in 12 states, among them Bayou City ER & Hospital in Texas and Green Bay ER & Hospital in Wisconsin. Nutex Health
Despite confirming that information was exfiltrated, Nutex said that, as of August 24, it had identified no material impact on its operations or financial reporting systems.
Based on the information currently available, the company also said it does not expect the cybersecurity incident to materially affect its business strategy, operations, financial condition, or financial results. That assessment could change as the investigation produces additional findings.
No ransomware or data-extortion group has been publicly identified as responsible for the intrusion. Nutex’s SEC disclosure also does not attribute the incident to a particular threat actor or state whether the company received an extortion demand.
For now, several important details remain unresolved, including the precise categories of stolen data, the number of individuals or organizations potentially affected, and the method attackers used to compromise the company’s systems.