Nutex Health Confirms Sensitive Data Stolen in August Cyberattack

Nutex Health, a Houston, Texas-based healthcare management and operations company that delivers care through 27 micro-hospitals, specialty hospitals, and outpatient departments in 12 U.S. states, has disclosed a cyberattack involving the exfiltration of data from some of its servers. Nutex is currently investigating the incident to determine the extent of data theft, including whether provider, employee, or patient data were exposed or stolen.

The incident was disclosed in an August 24, 2026, Item 8.01 Form 8-K filing with the U.S. Securities and Exchange Commission (SEC). Nutex explained that it recently learned of unauthorized activity related to data stored on its computer network. The company activated its incident response plan, implemented containment measures, and engaged an independent third-party cybersecurity response team and forensics experts to assist with the investigation and determine the extent to which data was exposed or stolen.

Per that filing, Nutex said the incident is still being assessed, and it has yet to determine whether private and confidential data was compromised in the incident. At the time, Nutex said it did not believe that the unauthorized access has, had, or is reasonably likely to have a material impact on the company’s business strategy, operations, financial condition or results of operations. Nutex did not disclose the name of the threat group behind the attack or whether it received a ransom demand, but it was aware that private and/or confidential information may be disclosed by the threat actor. At the time, no cybercriminal group had claimed responsibility for the attack.

Then, on August 31, 2026, Nutex filed an Item 1.05 Form 8-K filing with the SEC confirming that this is a material cybersecurity incident. The August 31, 2026, filing states that, “Based on the current status of the Company’s ongoing investigation, the Company believes that certain information maintained on the Company’s servers was accessed and exfiltrated by an unauthorized third party, including patient and employee, credentialed provider, business, and financial information that is private and/or confidential.”

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Nutex also confirmed that the threat actor has threatened to publish the stolen data; however, the company has not yet identified any material impact on its business operations or financial reporting systems. Nutex is continuing to assess the impacted data and the extent to which patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated.

The threat group behind the attack on Nutex appears to be The Gentlemen, a ransomware-as-a-service (RaaS) operation that first appeared in mid-2025 and significantly ramped up attacks in 2026. While the group’s attacks appear to be opportunistic, the healthcare sector accounts for around 9% of its attacks. The Gentlemen engages in double extortion tactics, exfiltrating sensitive data and demanding a ransom to decrypt files and prevent the release of stolen data.

The post Nutex Health Confirms Sensitive Data Stolen in August Cyberattack appeared first on The HIPAA Journal.

Oncology Firm Novocure Announces Cyberattack and Data Breach

The medical technology and oncology company Novocure has recently confirmed that patient and employee data were exposed in a recent cyberattack. Novocure is a publicly traded company with approximately 1,300 employees worldwide. Its global HQ is in Baar, Switzerland, and its U.S. headquarters is in Portsmouth, New Hampshire. The company has developed a novel non-invasive cancer treatment called Tumor Treating Fields (TTFields), which uses low-intensity, alternating electrical fields to disrupt the division of cancer cells.

Novocure explained in a September 1, 2026, Form-8K filing with the U.S. Securities and Exchange Commission (SEC), that it became aware of unauthorized access to some of its information systems via a subsidiary in mid-August 2026. Its incident response plan was activated, along with containment measures, and an investigation was launched, with assistance provided by third-party cybersecurity forensics experts.

While employee and patient data were stored on the compromised systems, the impact of the data breach was limited. Based on the investigation to date, approximately 1,400 U.S. patients had data exposed in the incident. The breach was limited to internal company ID numbers – no patient names or other identifying data were exposed. Fewer than 50 other patients in the Western United States had additional identifying information exposed, along with general contact information for all U.S. healthcare providers that the company works with, and general contact information for Novocure employees, including job titles and phone numbers. Novocure did not disclose how many employees had their contact information exposed in the incident.

Novocure said there was no unauthorized access to any of its medical treatment devices, no impact to operations, and all systems are fully functional. At the time of issuing the filing, Novocure said it does not believe that the incident will have any material impact or reasonably likely impact on its financial condition or results of operations, although the investigation into the incident is ongoing.  The threat group behind the attack and the nature of the incident were not disclosed.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Several medical technology companies have experienced cyberattacks this year, including Unlimited Technology Systems, CareCloud, Boston Scientific, Medtronic, Stryker, Abbot Laboratories, and iRhythm, although in this case, the impact appears to be limited. Other medtech companies have not been so fortunate. The cyberattacks on Unlimited Technology Systems and CareCloud involved unauthorized access to systems containing 3.8 million and 3.7 million patient records respectively, and the cyberattack on Boston Scientific disrupted operations globally.

The post Oncology Firm Novocure Announces Cyberattack and Data Breach appeared first on The HIPAA Journal.

Highland Oncology Group Settles Litigation Stemming From 2025 Ransomware Attack

Highlands Oncology Group, an Arkansas-based physician-owned community cancer care and research practice serving Northwest Arkansas, Southwest Missouri, and Southeast Oklahoma, has agreed to settle class action litigation stemming from a 2025 ransomware attack and data breach that affected 113,575 individuals.

The ransomware attack was identified by Highlands Oncology Group on or around June 2, 2025. While the attack was identified in early June, the investigation determined that the ransomware group first gained access to its network as early as January 21, 2025. Data accessed and/or exfiltrated included names, dates of birth, Social Security numbers, driver’s license/state identification numbers, passport numbers, credit/debit card numbers, financial account numbers, medical treatment information, medical record numbers, patient account numbers, and/or health insurance policy information.

The affected individuals were notified on August 1, 2025, and the first class action lawsuit was filed on August 5, 2025. In total, thirteen class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint as they had overlapping claims. The consolidated lawsuit – In re Highlands Oncology Group Data Breach Litigation – was filed in the Circuit Court for Washington County, Arkansas, where it is currently pending.

The consolidated lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, and invasion of privacy-intrusion upon seclusion. Highlands Oncology Group sought to have the consolidated class action complaint dismissed; however, after filing that motion, all parties engaged in settlement discussions, and following mediation, the terms of a settlement were negotiated. The settlement has recently received preliminary approval from the court.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Highlands Oncology Group will pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. Class members may submit a claim for one of two cash payments: A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $4,250 per class member, or a claim may be submitted for a one-time pro rata cash payment, estimated to be around $50 per class member.

Regardless of which cash payment is chosen, class members are eligible to enroll in three years of medical data monitoring services, which include a $1 million identity theft insurance policy. The deadline for opting out and objecting to the settlement is October 7, 2026. Claims must be submitted by October 22, 2026, and the final fairness hearing has been scheduled for November 6, 2026.

The post Highland Oncology Group Settles Litigation Stemming From 2025 Ransomware Attack appeared first on The HIPAA Journal.