Regulatory filing

Nutex Health Inc. disclosed a material cybersecurity incident

What the company disclosed

As disclosed in Item 8.01 of a Current Report on Form 8-K filed with the Securities and Exchange Commission on August 24, 2026 (the "Prior 8-K"), Nutex Health Inc. (the "Company") became aware of unauthorized activity involving data stored on its computer network. As disclosed in the Prior 8-K, the Company engaged an independent third-party cybersecurity response team and forensic experts, activated a cybersecurity response plan, implemented containment measures and notified law enforcement. Based on the current status of the Company's ongoing investigation, the Company believes that certain information maintained on the Company's servers was accessed and exfiltrated by an unauthorized third party, including patient and employee, credentialed provider, business and financial information that is private and/or confidential. The third party has threatened to post such information externally. To date, the Company has not identified any material impact on its business operations or financial reporting systems. The Company continues to assess whether, and to what extent, patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated and continues to evaluate the potential impact of the unauthorized activity on the Company, including any potential disclosure of private and/or confidential information by the third party. The Company continues to evaluate applicable regulatory and legal notification requirements, and the Company intends to make all required notifications based on its findings, including to impacted patients. Following the filing of the Prior 8-K, a purported class action complaint captioned Haley v. Nutex Health, Inc. , Case No. 4:26-cv-07197, was filed on August 27, 2026, against the Company in the United States District Court for the Southern District of Texas, Houston Division. The complaint was filed on behalf of a putative class of all individuals whose personally identifiable information and/or protected health information was allegedly accessed and/or acquired by an unauthorized party in connection with the incident. The complaint asserts claims for negligence, negligence per se, breach of third-party beneficiary contract, and unjust enrichment, and seeks, among other things, compensatory and consequential damages, injunctive relief, credit monitoring and identity theft insurance, and attorneys' fees and costs. At this stage, the Company is unable to predict the outcome of the litigation or estimate the potential impact of the incident on the Company's business strategy, operations, financial condition, results of operations or the trading price of the Company's common stock. Forward-Looking Statements This Current Report on Form 8-K contains "forward-looking statements" within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended. Such forward-looking statements are intended to be covered by the safe harbor provisions for forward-looking statements contained in the Private Securities Litigation Reform Act of 1995 and are included in this statement for purposes of complying with these safe harbor provisions. This document contains certain forward-looking statements with respect to current beliefs, understanding and expectations regarding the incident and its remediation and investigation. These forward-looking statements can be identified by the fact that they do not relate only to historical or current facts. Forward-looking statements often use words such as "estimate," "project," "predict," "will," "would," "should," "could," "may," "might," "anticipate," "plan," "intend," "believe," "expect," "aim," "goal," "target," "objective," "commit," "advance," "likely" or similar expressions that convey the prospective nature of events or outcomes. These forward-looking statements reflect current beliefs, understanding and expectations regarding the incident and its remediation and investigation. Factors that could cause actual results to differ materially from those indicated in the forward-looking statements include, but are not limited to: litigation to which the Company has or may become subject in connection with the incident; the results of the Company's ongoing investigation and analysis of the scope and details of the cybersecurity incident and the potential discovery of new and additional information related thereto; the Company's expectations regarding its ability to contain and remediate the cybersecurity incident, including the success of containment and remediation activities to date; any unauthorized release of the Company's data, including third-party data held by the Company, or the use of any such data for fraudulent purposes; potential loss or destruction of Company data or adverse impacts to the Company's operations; the impact of the cybersecurity incident on the Company's relationships with customers, employees, governmental regulators, and other stakeholders; diversion of management's attention from the Company's operations to addressing the cybersecurity incident; the legal, reputational, and financial risks resulting from the cybersecurity incident, including those that may arise from any potential regulatory inquiries; other reputational risk related to the cybersecurity incident; regulatory scrutiny of the cybersecurity incident; risks related to the availability of the Company's insurance coverage for losses and costs associated with the cybersecurity incident; and remediation and other additional costs that may be incurred by the Company in connection with the investigation and

remediation of the incident. Readers are cautioned that these forward-looking statements are not guarantees of future events or outcomes and they should not be unduly relied on, as they are based on information available to the Company and on management's current beliefs and expectations as of the date of this Current Report on Form 8-K and are therefore inherently uncertain and subject to risks, uncertainties, and assumptions that are difficult to predict, including those identified in our filings with the Securities and Exchange Commission, including the risk factors contained in our most recent Annual Report on Form 10-K and our Quarterly reports on Form 10-Q for the periods ended March 31, 2026 and June 30, 2026. We undertake no obligation to revise or update any forward-looking statements, including to reflect events or circumstances occurring after the date of the filing of this report, except to the extent required by law.

Quoted from the company’s own Form 8-K, Item 1.05, as filed with the US Securities and Exchange Commission. SEC filings are works of the US federal government and are in the public domain.

The record

Identity
Nutex Health Inc.identified by its SEC Central Index Key (0001479681)
Records affected
Records not disclosed
Sector
Services-Business Services, NECSIC 7389, from the company’s own filing
Occurred
Not disclosed
Disclosed
2026-08-31
First recorded here
2026-09-09

Sources (1)

One source so far.

  1. SEC EDGARFirst reported

    2026-08-31