As disclosed in Item 8.01 of a Current Report on Form 8-K filed with the Securities and Exchange Commission on August 24, 2026 (the "Prior 8-K"), Nutex Health Inc. (the "Company") became aware of unauthorized activity involving data stored on its computer network. As disclosed in the Prior 8-K, the Company engaged an independent third-party cybersecurity response team and forensic experts, activated a cybersecurity response plan, implemented containment measures and notified law enforcement.
Based on the current status of the Company’s ongoing investigation, the Company believes that certain information maintained on the Company’s servers was accessed and exfiltrated by an unauthorized third party, including patient and employee, credentialed provider, business and financial information that is private and/or confidential. The third party has threatened to post such information externally. To date, the Company has not identified any material impact on its business operations or financial reporting systems.
The Company continues to assess whether, and to what extent, patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated and continues to evaluate the potential impact of the unauthorized activity on the Company, including any potential disclosure of private and/or confidential information by the third party. The Company continues to evaluate applicable regulatory and legal notification requirements, and the Company intends to make all required notifications based on its findings, including to impacted patients.
Following the filing of the Prior 8-K, a purported class action complaint captioned Haley v. Nutex Health, Inc., Case No. 4:26-cv-07197, was filed on August 27, 2026, against the Company in the United States District Court for the Southern District of Texas, Houston Division. The complaint was filed on behalf of a putative class of all individuals whose personally identifiable information and/or protected health information was allegedly accessed and/or acquired by an unauthorized party in connection with the incident. The complaint asserts claims for negligence, negligence per se, breach of third-party beneficiary contract, and unjust enrichment, and seeks, among other things, compensatory and consequential damages, injunctive relief, credit monitoring and identity theft insurance, and attorneys’ fees and costs.
At this stage, the Company is unable to predict the outcome of the litigation or estimate the potential impact of the incident on the Company’s business strategy, operations, financial condition, results of operations or the trading price of the Company’s common stock.
Login to comment