BREACH2026-09-03T08:04:32.922878+00:005 min read

Your Hospital Records Could Go Public: Ransomware Gang Hit 27 US Facilities

The Gentlemen ransomware group stole patient files and financial data from Nutex Health's 27 US micro-hospitals and is threatening to publish everything.

Your Hospital Records Could Go Public: Ransomware Gang Hit 27 US Facilities

What Happened to Nutex Health, and Why It Affects You

A ransomware gang just walked out of 27 American hospitals with patient records, employee files, and financial data. The company is Nutex Health. The attackers are a group called The Gentlemen. And if Nutex doesn't pay the ransom, everything they stole goes public.

That's not a hypothetical. That's the threat sitting on a dark web leak site right now.


How Does a Double-Extortion Attack Actually Work?

Traditional ransomware locks your files and demands money to unlock them. Double extortion adds a second weapon: the attackers steal the data before they encrypt it.

Now the victim faces two separate problems. Even if you restore from backups and refuse to pay, the criminals still hold copies of everything they grabbed. They threaten to publish it on their leak site unless you pay. It's a hostage situation where the hostages are your patients' most sensitive personal information.

The Gentlemen operate as a ransomware-as-a-service group. That means they built the tools and infrastructure, then rent access to other criminals who do the actual attacks. The profits get split. The victims still suffer the same way.


The Numbers: What We Know

Nutex Health runs 27 facilities, micro-hospitals, specialty hospitals, and outpatient clinics, across 12 states, headquartered in Houston, Texas.

The company first reported unauthorized network access to the SEC on August 24, 2026, using a routine disclosure form called an 8-K. One week later, on August 31, 2026, they escalated that filing to acknowledge a material cybersecurity incident. That escalation is significant. It means the company concluded the breach was serious enough to matter to investors.

Confirmed stolen data includes:

  • Patient information
  • Employee records
  • Credentialed provider data
  • Business and financial information

Nutex says it has not identified a material impact on operations or financial reporting systems. They also say they will notify affected patients. But they have not disclosed how many people were impacted.

A class-action lawsuit was filed in Texas shortly after the disclosure.


Should You Be Worried If You Used a Nutex Facility?

Yes. If you or a family member received care at any Nutex Health location across any of those 12 states, your records may be in that stolen dataset.

What makes medical data uniquely dangerous is that you cannot change it. You can cancel a credit card. You can get a new bank account number. You cannot get a new medical history, a new Social Security number without a long and painful process, or a new date of birth.

Medical records sell for significantly more on criminal markets than simple financial data. They contain your diagnoses, medications, insurance information, and provider details. Criminals use that combination for insurance fraud, prescription fraud, and identity theft.

The fact that criminals are threatening public release makes this worse. Once data is published on a leak site, it is out there permanently. Other bad actors download it. It spreads. Notification letters can't undo that.


What to Do Right Now

You don't need to wait for Nutex to contact you. Take these steps today.

  1. Freeze your credit at all three bureaus. Go directly to Equifax, Experian, and TransUnion and place a security freeze. It's free and it's the single most effective thing you can do to prevent someone from opening new accounts in your name. A freeze doesn't affect your existing accounts.

  2. Set up fraud alerts. If you don't want to freeze, place a fraud alert. It requires lenders to verify your identity before extending new credit. Also free, also effective as a starting point.

  3. Watch your Explanation of Benefits statements. If your insurer sends EOB notices, read them. A claim you don't recognize is a red flag that someone is billing your insurance.

  4. Contact your insurer directly. Ask if they have any process for flagging potential medical identity theft on your account. Some do. Most will at least note your concern.

  5. Start removing your data from data broker sites. Services like DeleteMe or similar tools can help, or you can submit opt-out requests directly to major brokers. Your data is already in many places. Reducing the attack surface matters over time.

  6. Enable strong authentication everywhere. Passkeys where available, then hardware security keys, then authenticator apps. Avoid SMS codes if you can. Medical identity theft often leads to account takeovers on connected services.

  7. Watch for phishing. When criminals have your name, address, provider name, and medical details, they can write very convincing fake letters or emails. They will pretend to be Nutex, your insurer, or a government agency. Any communication asking you to click a link or provide more information should be treated with skepticism.


The Systemic Problem That Doesn't Get Said Enough

Healthcare is one of the most targeted sectors in the world by ransomware gangs, and one of the least defended. The margins are thin. The legacy systems are old. The staff are overwhelmed. And the data inside those systems is extraordinarily valuable.

Every time a company discloses a breach like this, weeks after the attack, with no count of affected patients, it reflects an industry that has not treated patient data as the critical infrastructure it actually is.

You trusted Nutex with information you had to share to get care. That trust created an obligation. Patients don't get to choose not to hand over their records when they walk through an emergency room door.

The lawsuit in Texas is just the beginning of the accountability conversation.


Do this now:

  • Freeze your credit (free at all three bureaus)
  • Set up fraud alerts
  • Review recent insurance EOBs for unfamiliar claims
  • Enable passkeys or an authenticator app on your key accounts
  • Treat any Nutex-related communications with caution until you can verify the source

Sources

WHAT TO DO RIGHT NOW
  1. 01Go to haveibeenpwned.com and check your email address right now
  2. 02Change your password on the breached service — use a unique password you do not use anywhere else
  3. 03Enable two-factor authentication (2FA) on that account if available
  4. 04Monitor your bank statements and credit report for unusual activity over the next 90 days
RECOMMENDED PROTECTIONAFFILIATE

AuraAll-in-one identity theft and scam protection with real-time alerts

Get Aura
Check Have I Been Pwned →
// FAQ

Common Questions About Breach

What should I do immediately after a data breach?

Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.

How long do companies have to notify me after a data breach?

In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.

Should I freeze my credit after a data breach?

Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.

// RELATED

More in breach

153 Million Driver's Licenses Are Being Sold on the Dark Web Right Now
2026-09-08T08:03:13.929805+00:00 · 5 min read
Hasbro Kept Quiet for 5 Months While Hackers Had Workers' SSNs and Bank Info
2026-09-05T08:04:13.891376+00:00 · 5 min read
Your Doctor Used This Company to Store Your Records. Hackers Took 9.5 Million of Them.
2026-09-02T08:09:38.315513+00:00 · 5 min read

Stay invisible. Follow @hack_decoded