Houston-based Nutex Health has disclosed that an unauthorized third party accessed and exfiltrated data from its computer network.
The publicly traded microhospital operator said it recently detected the unauthorized activity and has engaged an independent third-party cybersecurity response team and forensic experts, according to an Aug. 24 SEC filing. The company activated its cybersecurity response plan, implemented containment measures and notified law enforcement.
The company is still determining what data was compromised. Nutex said it continues to assess whether patient, employee, credentialed provider, confidential business and financial information, or intellectual property was accessed or acquired.
As of the filing date, Nutex said it has not identified any material impact on its business operations or financial reporting systems. The company said it is evaluating regulatory and legal notification requirements and intends to notify affected patients if applicable.
Nutex Health operates 28 microhospitals and hospital outpatient departments across 12 states.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.