Nutex Health Filed Under 8.01. Seven Days Later It Filed Under 1.05. The Class Action Landed in Between.

On August 24, 2026, Nutex Health told the SEC about a cyber incident under Item 8.01 — the catch-all for other events. On August 31 it filed again under Item 1.05, the dedicated Material Cybersecurity Incidents item. On August 27, in between, a class action was filed. This is the SEC disclosure regime working as designed, and it is uncomfortable.
What happened, in order
August 24, 2026. Nutex Health Inc. (NASDAQ: NUTX) filed a Form 8-K under Item 8.01 — Other Events. The company stated it had recently learned of unauthorized activity involving data stored on its computer network, engaged third-party forensics, activated its response plan, implemented containment, and notified law enforcement. It stated it did not believe the incident had had, or was reasonably likely to have, a material impact.
August 27, 2026. A purported class action, Haley v. Nutex Health, Inc., Case No. 4:26-cv-07197, was filed in the Southern District of Texas.
August 31, 2026. Nutex filed again, under Item 1.05 — Material Cybersecurity Incidents. The company now stated that certain information on its servers was accessed and exfiltrated by an unauthorized third party, including patient and employee, credentialed provider, business and financial information that is private and/or confidential, and that the third party has threatened to post such information externally.
Seven days between filings. Three days from the first filing to litigation. Nutex operates micro-hospitals, specialty hospitals, and outpatient departments across roughly 24 facilities in 11 to 12 states.
Why the two items are different
Item 8.01 is the catch-all a registrant uses for events it elects to disclose. It carries no materiality determination and no fixed deadline.
Item 1.05 is the SEC's dedicated cybersecurity item, effective since December 2023. It requires filing within four business days of determining that an incident is material — not four days from the incident, four days from the determination.
That construction is what makes the sequence legible. Filing under 8.01 is a statement that the company has not concluded the incident is material. Filing under 1.05 is a statement that it now has. The gap between those two filings is a documented record of a materiality judgment that changed.
The four-business-day clock under Item 1.05 runs from the materiality determination, not from the incident. That makes the determination date itself a decision — and a decision a regulator can examine.
Neither filing was wrong
This is worth stating plainly, because the sequence invites a cynical read that the facts do not clearly support.
On August 24, Nutex knew there had been unauthorized activity. Forensics were underway. The scope was unknown. Concluding that materiality had not yet been established is a defensible position, and filing under 8.01 to disclose what was known is arguably better practice than saying nothing while the investigation ran.
By August 31, the company knew considerably more: that data had been exfiltrated, that it included patient and employee information, and that the attacker had threatened publication. On those facts a materiality determination is reasonable, and the four-day clock started when it was made.
Both filings can be individually correct. The sequence is still a permanent, dated, public record that the company assessed the same incident two different ways inside a week — and every future adversary now has it.
What the record has to survive
Plaintiffs' counsel will argue the company knew enough on August 24 and chose the lighter filing.
The SEC, if it examines the matter, will ask what facts were known on each date and what analysis supported each determination.
An acquirer's diligence team will ask the same question for a different reason: what it says about how this management team makes judgment calls under pressure.
In every case the answer depends on a single thing: whether the materiality analysis was documented contemporaneously. A memo dated August 24 setting out what was known, who participated, what standard was applied, and why the conclusion was reached, converts the sequence from an apparent walk-back into a documented judgment that was revisited when new facts arrived. Without that memo, the company is reconstructing its own reasoning after the fact, in front of people who assume the worst.
The healthcare multiplier
Nutex runs three clocks simultaneously.
SEC. Item 1.05, four business days from materiality determination.
HIPAA. Breach notification to HHS and to affected individuals, on its own timeline, independent of anything the SEC requires. Notifications above the threshold appear on a public list.
State law. Nutex operates across 11 to 12 states. Each has its own notification statute with its own trigger, timeline, and attorney general reporting requirement.
These clocks do not synchronize and satisfying one does not satisfy the others. A company can be timely with the SEC and late with a state AG.
What deal teams and boards should take from this
Pre-agree the materiality framework. Deciding what makes a cyber incident material, and who decides, is a governance exercise to complete before an incident. Doing it during one, with incomplete forensics and a four-day clock running, produces exactly this sequence.
Document contemporaneously. The memo is the control. It costs an hour and it is the entire defense.
Understand that the determination date is itself a decision. Because the clock runs from the determination rather than the incident, when a company decides is as examinable as what it decided.
Add disclosure history to the diligence checklist. A target's 8-K history, and the documented basis for any materiality call it made, is a direct read on management's judgment. Read it alongside the SEC disclosure rule and the SolarWinds CISO charges, which established that individuals can be held personally accountable for cyber disclosure accuracy.
Litigation now moves faster than forensics. The complaint arrived three days after the first filing and four days before the company had finished enough investigation to file under 1.05. Any disclosure plan assuming there is time between disclosure and litigation is working from an outdated assumption.
Full factual record: Nutex Health 2026 in the Breach Library.
Nutex Health has not been accused of doing anything improper, and on the public facts it appears to have moved reasonably as its understanding developed. That is what makes the sequence useful. This is what the disclosure regime looks like working correctly, and it still produced a permanent public record of a materiality judgment that changed inside seven days, with a class action filed in the gap. Every public company will face this. The only variable is whether the memo explaining the first determination was written on the day it was made.
Cloudskope advises boards and general counsel on the exposure behind disclosure decisions: what the environment contains, whether an intrusion is present, and whether public security representations match operational reality. SARTUS answers the first two in a bounded six-day engagement.
.png)
.png)