Nutex Health disclosed the same data-theft incident twice in seven days — first as an Item 8.01 “other event,” then, in an after-close filing on Monday, under Item 1.05, the item reserved for cybersecurity incidents a company has determined to be material.
What happened
Nutex Health Inc. (NASDAQ: NUTX), the Houston-based physician-led operator of micro-hospitals and outpatient clinics, filed a Form 8-K with the Securities and Exchange Commission on Monday, August 31, 2026. EDGAR stamped it accepted at 4:25 p.m. ET, after the closing bell.
The filing carries one item: Item 1.05, Material Cybersecurity Incidents. It is accession number 0001628280-26-059602, and its cover-page XBRL sets the amendment flag to false. That detail matters: this is not an 8-K/A amending an earlier report but a new current report, filed under a different item, about an incident the company had already disclosed.
The earlier disclosure was accession number 0001628280-26-058606, filed Monday, August 24, 2026, with a period of report of the same date. It carries a single item as well: Item 8.01, Other Events. In it, Nutex said it had identified unauthorized activity on its computer network, had engaged outside cybersecurity experts and notified law enforcement, and believed “certain information maintained on the Company’s servers was accessed and exfiltrated by an unauthorized third party.” The August 24 filing added that the company “does not believe that the unauthorized access has had, or is reasonably likely to have, a material impact” on its business strategy, operations, financial condition, or results of operations.
The August 31 filing repeats the substance. The company again says information on its servers was accessed and exfiltrated, again identifies patient, employee, and business or financial data as the categories under assessment, and again states that it has not identified any material impact on its business operations or financial reporting systems. It adds that the unauthorized party has threatened to publish the stolen information, that Nutex intends to make the notifications its findings require, including to affected patients, and that a putative class action — Haley v. Nutex Health, Inc., No. 4:26-cv-07197, filed August 27, 2026, in the U.S. District Court for the Southern District of Texas — is now pending. The company says it cannot predict the outcome of that suit.
What the August 31 filing does not contain is a sentence saying the company has now determined the incident to be material. Item 1.05 exists for exactly that determination. The filing arrives under that item while still carrying the no-material-impact language that belonged to the August 24 Item 8.01 report.
Nutex has not published a record count or named an attacker, and no extortion group has publicly claimed the intrusion. The filings give no date of intrusion and no date of discovery, only the August 24 date of earliest event reported.
Why it matters
The two items are not interchangeable, and the distinction was built deliberately. When the cybersecurity disclosure rules took effect, the SEC’s Division of Corporation Finance addressed a specific worry in a May 21, 2024 statement: companies were filing under Item 1.05 defensively, before they had made any materiality determination, and the result was that the item stopped meaning anything. The staff’s answer was to point voluntary and undetermined disclosures to Item 8.01 and to keep Item 1.05 for incidents actually determined material, so that investors could tell one from the other at a glance.
Read against that, the Nutex sequence is the well-behaved one. A company discovers an intrusion, does not yet know how bad it is, files under 8.01 to get the fact on the record, and moves to 1.05 when the determination lands. That is the path the staff described. Item selection is the signal, and a company that changes item is telling investors something changed.
Which is why the missing sentence is the finding. If a determination was made between August 24 and August 31, the second filing is where it should appear, and it does not appear there. Instead the reader gets an Item 1.05 heading sitting above language stating that no material impact has been identified — two claims that point in opposite directions, in the same document, without a word reconciling them.
There are readings that do not involve a determination at all. The class action landed on August 27, three days after the first filing and four days before the second, and counsel weighing a securities-fraud tail risk may simply prefer the stronger item on the theory that no one is ever sued for filing a 1.05 where an 8.01 would have done. Nutex has not said which, and this publication is not going to guess. The observable fact is the item change and the absence of any explanation for it.
The practical consequence lands on anyone who tracks 8-K cyber disclosures programmatically, which now includes a good deal of the insurance, credit, and vendor-risk industry. Item 1.05 is a machine-readable flag. Dashboards count it, screens sort on it, and a fair number of downstream systems treat a 1.05 as an issuer’s own statement that an incident was material. When the body of a 1.05 filing says the opposite of the item it is filed under, the flag and the text disagree, and only the flag travels. This is a recurring shape on this site: the structured field and the prose diverge, and the structured field is the one everyone actually reads.
The healthcare context sharpens it. Nutex operates emergency and micro-hospital facilities, so the records on those servers are patient records, and the notification obligations that follow are not SEC obligations. HIPAA breach notification and the state attorney general regimes run on their own clocks and their own thresholds, and none of them care what item an 8-K was filed under. A company can hold that an incident is immaterial to its financial condition and still owe individual notice to a large number of people. Those are simply different questions, and the securities filing answers only one of them. Readers waiting for the 8-K to tell them how many people were affected are waiting for the wrong document; that number, when it exists, will surface in state attorney general portals and in the U.S. Department of Health and Human Services breach portal, and it will surface later.
Finally, the timing is worth naming. The second filing was accepted at 4:25 p.m. ET, half an hour after the close. That is a legitimate and extremely common filing window. It is also the window in which disclosures reliably get the least attention, which is why this publication checks EDGAR again at the end of the day rather than only in the morning.
What to do
If you are a Nutex patient or employee: there is nothing to act on yet beyond ordinary hygiene. The company says it intends to notify affected individuals once its assessment identifies them. Watch for a mailed notice, and be skeptical of email or phone contact claiming to be that notice — breach notifications are a favored pretext, and this one is now public enough to imitate.
If you screen 8-K cyber filings: stop treating the item number as the materiality determination. Check whether the body of the filing contains an affirmative determination sentence, and flag filings where it does not. The Nutex pair is a clean test case for that logic: an 8.01 and a 1.05, seven days apart, with substantially the same body text.
If you are a filer: if you move an incident from Item 8.01 to Item 1.05, say in the second filing what changed. A one-sentence statement that the company has determined the incident to be material costs nothing and removes the ambiguity entirely. Leaving the earlier no-material-impact language in place under the new item creates a document that contradicts itself on its face.
If you are a Nutex counterparty: the exfiltrated categories named in the filings include business and financial information, and Nutex says the unauthorized party has threatened publication. That is the company’s characterization, not a confirmed leak. Treat it as a reason to check what of yours sits in their environment, not as a reason to assume it is public.
Sourcing note
Both 8-K filings were read on EDGAR: accession 0001628280-26-058606, filed August 24, 2026 under Item 8.01, and accession 0001628280-26-059602, filed August 31, 2026 under Item 1.05, with acceptance time and item designation taken from the filing index and the amendment flag from the cover-page XBRL. Quoted language is reproduced from the filings as filed. A third Nutex 8-K filed August 13, 2026 also carries Item 8.01 but concerns the Fifth Circuit’s Texas Medical Association v. HHS decision on the No Surprises Act and is unrelated to the incident; it is noted here so that anyone counting Nutex 8.01 filings does not miscount.
The class action caption, number, court, and filing date are as stated in the August 31 filing; the docket itself was not retrieved. No record count, no date of intrusion, and no date of discovery appears in either filing, and none is asserted here. No extortion group had publicly claimed the intrusion at the time of writing; the threat to publish is reported by Nutex, not observed here. Trade coverage of the August 24 filing was used only to confirm that the earlier disclosure had been reported.
Unresolved: whether Nutex made a materiality determination between August 24 and August 31, and if so why the August 31 filing does not say so. This site did not seek comment. Also unresolved: how many individuals are affected, which will not come from EDGAR.
