Severity Daily

IT and AI security incidents, checked against the primary source

Tag: EDGAR

  • Nutex Health’s stolen data has been published online, and the update goes back under Item 8.01 with the materiality finding unchanged

    Nutex Health’s stolen data has been published online, and the update goes back under Item 8.01 with the materiality finding unchanged

    Eleven days after moving its breach disclosure up to Item 1.05, Nutex Health filed the update that the data is public under Item 8.01 — and said its assessment of materiality has not changed.

    What happened

    Nutex Health Inc. (NASDAQ: NUTX), a Houston company that operates 28 hospitals across 12 states, issued a press release on September 10, 2026, headed “NUTEX HEALTH PROVIDES UPDATE REGARDING CYBERSECURITY EVENT.” It was furnished to the SEC as an exhibit to an 8-K that EDGAR accepted at 5:53 p.m. ET on September 10 and dated September 11, 2026. The filing is accession 0001628280-26-061432, and it lands under Item 8.01, Other Events, together with Item 9.01.

    The substance of the update is that the stolen data is now public. In the company’s words: “The unauthorized third party has published on its website the data that was allegedly obtained.” Nutex is not yet willing to say the published material is genuinely its own. It says it is, “together with its cybersecurity experts and advisors, in the process of downloading, processing and analyzing the data” in order “to determine its contents, scope, and authenticity,” and that “due to the volume of data involved, the Company expects this process and review to take several weeks.”

    On the question the item heading raises, the release is explicit: “Based on the information currently available, the Company’s assessment of the materiality of this event, as set forth in the August 31, 2026 8-K, has not changed.”

    On notification: “The Company intends to make all required notifications based on its findings, including to impacted patients and employees.” On litigation: “Several purported class action complaints were filed against the Company in the United States District Court for the Southern District of Texas, Houston Division.” Law enforcement has been notified; no agency is named.

    What the release does not contain is as notable as what it does. There is no count of affected individuals, no volume of data, no date for the intrusion, and no date for the publication. The unauthorized third party is not named, and neither is the site the data was published on.

    The filing path so far

    This is the third 8-K Nutex has filed on this incident, and the item headings have moved twice.

    On August 24, 2026 (accession 0001628280-26-058606), Nutex disclosed under Item 8.01 that unauthorized activity had accessed and exfiltrated information from its servers, and stated that it “does not believe that the unauthorized access has had, or is reasonably likely to have, a material impact” on its business.

    On August 31, 2026 (accession 0001628280-26-059602), it refiled the same incident under Item 1.05, Material Cybersecurity Incidents — the heading the SEC reserves for incidents a registrant has determined to be material — while keeping the no-material-impact language. Severity Daily covered that filing in Nutex Health moved its breach disclosure to Item 1.05 seven days after filing it under 8.01.

    The September 10 update goes back to Item 8.01. It is a fresh 8-K, not an 8-K/A amending the Item 1.05 filing, and it does not restate or withdraw the materiality determination it points back to. It says that determination has not changed.

    Why it matters

    Item 1.05 is not a severity label. It is a disclosure trigger with a four-business-day clock attached, and it fires on a registrant’s determination that an incident is material. Item 8.01 is the catch-all for anything a company chooses to disclose. The SEC’s own guidance has been consistent that a company should not file under 1.05 unless it has made the materiality determination, precisely so that the heading keeps meaning something — and the practical consequence is that a great deal of downstream machinery reads the item number as the signal.

    That machinery now has a problem with this company. Anything keying on item headings sees a registrant that escalated to the material-incident heading on August 31 and then filed the development that most obviously bears on materiality — the data is out, and plaintiffs are lining up — under the heading for other events, with an express statement that nothing about the materiality picture has moved.

    It is worth being precise about what is and is not odd here. Filing an update under 8.01 is not itself improper; registrants do it routinely, and an amendment is required only where the original filing was materially deficient. A materiality determination that does not change is likewise a legitimate position: publication of exfiltrated data is not automatically material to a hospital operator’s financial condition, and the company may well be right. What is unusual is the combination — the heading moving up, then back down, with the same “no material impact” finding carried through all three filings, and no explanation in any of them for why the heading moved in the first place.

    Severity Daily has now written this shape three times in as many weeks. Park Dental Partners filed under Item 1.05 and then said it had found no material impact. NovoCure disclosed under 8.01 and wrote its own 1.05 trigger into the filing. Boston Scientific went the other way, escalating to 1.05 with a guidance cut and still saying nothing about data. The heading and the finding are drifting apart across filers, and Nutex is the clearest case yet because the same company has now used both headings for the same incident without saying what distinguishes them.

    The other thing to take from this filing is the authenticity language, which is the honest part of it. “Data that was allegedly obtained,” and a review to determine “contents, scope, and authenticity,” is the correct posture toward a leak-site dump that has not been verified. It is also a reminder of what nobody can tell you yet. The published set may be complete, partial, padded, or recycled. Until the review finishes — several weeks, by the company’s own estimate — any figure attached to this incident from outside the company is a claim about a dataset whose provenance the victim has not confirmed. If a record count appears in coverage of this breach before Nutex publishes one, it came from the party that published the data.

    What to do

    There is no patch here and no action item for most readers. What there is, for three specific audiences:

    If you are a Nutex patient or employee, the company says notifications will follow its review, and that review is expected to take several weeks. No notification has gone out yet, and no count exists. Nothing in the filing suggests waiting for a letter before placing a credit freeze.

    If you consume SEC filings programmatically — and a lot of vendor risk tooling now does — do not treat the item number as the materiality state. This incident has produced an 8.01, a 1.05, and another 8.01, with one unchanged determination underneath all three. Key on the text.

    If you are drafting your own disclosures, the gap Nutex leaves open is the one to close: when a heading changes, say in the filing what changed. Three filings in, an outside reader still cannot tell whether the August 31 escalation reflected a determination, an abundance of caution, or a correction.

    Sourcing note

    This story is written from the filing. The 8-K and its exhibit were read directly on EDGAR at accession 0001628280-26-061432 (CIK 0001479681). Submission type, item information, acceptance timestamp of 5:53 p.m. ET on September 10, 2026, filed-as-of date of September 11, 2026, and period of report of September 10, 2026 are taken from the filing’s index headers. All quoted language is from the exhibit, the press release dated September 10, 2026 from Houston.

    The August 24 and August 31 filings are identified by accession number from Severity Daily’s earlier reporting on them; the quoted “does not believe that the unauthorized access has had, or is reasonably likely to have, a material impact” is from the August 24 filing. The class action previously identified in that reporting is Haley v. Nutex Health, Inc., No. 4:26-cv-07197, filed August 27, 2026 in the Southern District of Texas; the September 10 release refers to “several purported class action complaints” in that district without docket numbers, and the individual dockets were not retrieved for this story.

    Unresolved: the number of individuals affected, the intrusion date, the publication date, the identity of the party that published the data, whether that data is authentic, and why the item heading moved from 8.01 to 1.05 and back. No regulator is named in the filing, and no HHS Office for Civil Rights entry was confirmed — the OCR breach portal is a dynamic application and is not retrievable by automated fetching, which is a standing gap in confirming affected counts for healthcare incidents.