Nutex Health 2026: The Seven Days Between Item 8.01 and Item 1.05

6 minute read
August 24, 2026 (Item 8.01) / August 31, 2026 (Item 1.05)
Share Article
BREACH INTELLIGENCE
breach date

August 24, 2026 (Item 8.01) / August 31, 2026 (Item 1.05)

Industry

Healthcare / Hospital Operations

Severity

High

Records Exposed

Undisclosed

Financial Impact

3 days to litigation

Breach Summary

On August 24, 2026, Nutex Health Inc. (NASDAQ: NUTX) told the SEC it had learned of unauthorized activity on its network. It filed that disclosure under Item 8.01 — the catch-all for other events a company chooses to report.

On August 31, seven days later, Nutex filed again. This time under Item 1.05: Material Cybersecurity Incidents. In between, on August 27, a purported class action was filed against the company in the Southern District of Texas.

The conversion from 8.01 to 1.05 is the story. It is the SEC disclosure regime working exactly as designed and exactly as uncomfortably as companies feared: a filing choice made under uncertainty, revisited a week later when the facts caught up.

What Happened

Nutex Health operates micro-hospitals, specialty hospitals, and hospital outpatient departments across roughly 24 facilities in 11 to 12 states. It is publicly traded on NASDAQ under NUTX.

The first filing. On August 24, 2026, Nutex filed a Form 8-K under Item 8.01 stating it had recently learned of unauthorized activity involving data stored on its computer network. The company said it had engaged an independent third-party cybersecurity response team and forensic experts, activated its cybersecurity response plan, implemented containment measures, and notified law enforcement. It stated it did not believe the unauthorized access had had, or was reasonably likely to have, a material impact on the business.

The lawsuit. On August 27 — three days later — a purported class action captioned Haley v. Nutex Health, Inc., Case No. 4:26-cv-07197, was filed in the United States District Court for the Southern District of Texas, Houston Division.

The second filing. On August 31, Nutex filed again, this time under Item 1.05, Material Cybersecurity Incidents. The company stated that based on the current status of its investigation it believed certain information maintained on its servers was accessed and exfiltrated by an unauthorized third party, including patient and employee, credentialed provider, business and financial information that is private and/or confidential, and that the third party has threatened to post such information externally.

Nutex maintained that it had not identified any material impact on business operations or financial reporting systems. It continues to assess scope and evaluate regulatory and legal notification requirements, including notification to affected patients.

Attack Vector Detail

Nutex has not disclosed the initial access vector, and as of this writing no threat actor has publicly claimed the attack — unusual for an incident where the attacker has threatened publication. BleepingComputer and SecurityWeek both noted the absence of a leak-site listing.

What the filings do establish: data was accessed and exfiltrated from servers, and the third party threatened to post such information externally. That is double extortion without the encryption half, or with encryption that did not succeed. The company reported no material impact on business operations or financial reporting systems, which is consistent with a data-theft-only intrusion rather than a deployment of ransomware across production.

The absence of a public claim has two plausible explanations. Either negotiations are ongoing and the actor is withholding publication as leverage, or the actor operates without a public leak site. Both are worth watching.

Breach Pattern Timeline

  • August 24, 2026 — Nutex files Form 8-K under Item 8.01. Engages third-party forensics, activates response plan, implements containment, notifies law enforcement. States no material impact.
  • August 27, 2026Haley v. Nutex Health, Inc., Case No. 4:26-cv-07197, filed in the Southern District of Texas. Three days after the 8.01.
  • August 31, 2026 — Nutex files under Item 1.05, Material Cybersecurity Incidents. Confirms patient, employee, credentialed provider, business, and financial information was accessed and exfiltrated, and that the third party has threatened publication.
  • Ongoing — Scope assessment continues. No threat actor has publicly claimed the attack. Regulatory notification obligations, including to affected patients, under evaluation.

Executive Lessons

Five questions for any public company board:

  1. Who decides materiality for a cyber incident, and on what documented analysis? If the answer is counsel and the CFO, informally, that is a governance gap.
  2. Have we pre-agreed the 8.01 vs. 1.05 decision framework? Deciding the framework during an active incident, under time pressure, with incomplete forensics, produces the Nutex sequence.
  3. What is our four-business-day clock discipline? Item 1.05 requires filing within four business days of the materiality determination — not of the incident. The determination date is therefore itself a decision with consequences.
  4. Do our public statements about security survive the incident we are actually going to have? Read the 10-K risk factors and any customer-facing security representations against the current facts.
  5. How fast can litigation reach us? Three days, in this case.

Private Equity Implications

For sponsors holding healthcare assets or any public portfolio company, Nutex is a compact lesson in disclosure risk as a distinct exposure from cyber risk.

The 8.01-to-1.05 conversion is a documented change in materiality judgment. Every subsequent adversary — plaintiffs' counsel, the SEC, a short seller, an acquirer's diligence team — now has a dated record of the company assessing the same incident two ways within a week. Whether that record is defensible depends entirely on whether the underlying determination was documented contemporaneously.

Litigation arrived in three days. The class action landed before the company had finished scoping the incident and before it filed under 1.05. Disclosure timing is now a litigation trigger on a timescale shorter than most forensic investigations.

Healthcare data plus public company status is the highest-friction combination. HIPAA notification obligations, state statutes across every operating jurisdiction, SEC materiality analysis, and securities litigation all run concurrently on different clocks.

For diligence: a target's incident disclosure history, and the documented basis for any materiality determination it made, belongs in the data room. Read against the SEC cybersecurity disclosure rule and the SolarWinds CISO charges, which established individual accountability for cyber disclosure accuracy.

How Cloudskope Can Help

Cloudskope advises boards and general counsel on the exposure this incident illustrates: what the environment actually contains, whether an intrusion is present, and whether public security representations match operational reality. SARTUS™ answers the first two in a bounded six-day engagement — three days of assessment across identity, cloud posture, credential exposure, and active-compromise indicators, three days of done-for-you remediation, consolidated risk register mapped to NIST 800-53 and the CIS Benchmarks.

Book a strategy session.

Frequently Asked Questions

What happened in the Nutex Health data breach?

Nutex Health disclosed on August 24, 2026 that it had learned of unauthorized activity on its network. A follow-up filing on August 31 confirmed that patient, employee, credentialed provider, business, and financial information had been accessed and exfiltrated by an unauthorized third party, which threatened to publish it.

What is the difference between Item 8.01 and Item 1.05?

Item 8.01 is the general catch-all for other events a company elects to report. Item 1.05 is the SEC's dedicated Material Cybersecurity Incidents item, required within four business days of determining an incident is material. Filing under 8.01 signals the company has not concluded the incident is material; converting to 1.05 signals it now has.

Why does the filing sequence matter?

Nutex filed 8.01 on August 24, a class action was filed August 27, and Nutex filed 1.05 on August 31. The seven-day conversion documents a materiality determination that changed. Regulators and plaintiffs read that sequence as evidence about what the company knew and when.

How many people were affected?

Nutex has not disclosed a figure. The company continues to assess the scope of patient, employee, credentialed provider, business, financial, and intellectual property information that may have been accessed.

Who was responsible?

No threat actor has publicly claimed the attack as of this writing, which is notable given that the attacker has threatened publication of the stolen data.