TechNewsReel
Live

Nutex Health Confirms Data Theft After 'The Gentlemen' Ransomware Attack

The US healthcare operator faces a class-action lawsuit after sensitive patient and financial records were exfiltrated.

TechNewsReel Newsroom · September 11, 2026

Nutex Health, a US-based healthcare operator, has confirmed that an unauthorized third party breached its internal network and stole confidential files. The incident exposed sensitive records belonging to patients, employees, and providers, as well as corporate financial data.

In SEC filings, Nutex Health stated that certain information maintained on its servers was accessed and exfiltrated. The ransomware group known as 'The Gentlemen' claimed responsibility for the breach, listing the company on its dark web portal. The group operates under a double-extortion model, stealing data to pressure victims into paying ransoms to prevent public release.

Legal and Financial Fallout

The breach triggered immediate legal action. On August 27, 2026, a class-action lawsuit, Haley v. Nutex Health, Inc. (Case No. 4:26-cv-07197), was filed in the U.S. District Court for the Southern District of Texas. The lawsuit alleges the company was negligent and committed a breach of contract by failing to protect the sensitive data of those it serves.

Nutex Health (NASDAQ: NUTX) is a significant player in the for-profit healthcare sector, operating 28 facilities across 12 US states. The scale of these operations amplifies the breach's impact; in 2025, the operator reported annual revenue of $875 million and held a market capitalization of $1.28 billion.

Industry Implications

This attack underscores the persistent vulnerability of micro-hospital networks to sophisticated cyber threats. The involvement of 'The Gentlemen'—a ransomware-as-a-service (RaaS) syndicate that emerged around mid-2025—highlights a trend where specialized criminal groups provide the tools and infrastructure for attacks on critical infrastructure.

For the healthcare industry, the exfiltration of Protected Health Information (PHI) is particularly damaging. Unlike encrypted systems that can be restored from backups, stolen data creates a permanent risk of identity theft and fraud for patients and staff, often leading to prolonged litigation and regulatory scrutiny.

Current Status

Following the detection of the intrusion, Nutex Health hired external forensic specialists to investigate the scope of the breach and notified law enforcement agencies. While the company acknowledged the theft of data via its Form 8-K filing dated August 31, 2026, the full extent of the compromised records remains under investigation. Observers are now watching to see if the attackers leak the stolen data or if a settlement will be reached in the pending class-action suit.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.