Nutex Health confirms breach of patient and employee data by ransomware gang
Nutex Health disclosed that a ransomware group stole confidential patient, employee, provider, business and financial records and is threatening to release the data.
Nutex Health revealed that attackers accessed and removed a range of private data, including patient, employee, provider, business and financial details, and have threatened to publish the material. The breach was initially reported under a generic SEC filing on August 24, but the company later updated the filing to classify it as a material cybersecurity incident as the investigation clarifies the scope of the theft. The ransomware-as-a-service group known as The Gentlemen added Nutex to its public leak site and claimed responsibility, though it provided no supporting evidence.
The gang is known for targeting organisations outside the former Soviet bloc with sophisticated, self-propagating encryptors. Nutex operates 28 hospitals across 12 U.S. states and has said the breach has not yet caused a material effect on its operations or financial reporting. A proposed class-action suit was lodged on August 27 on behalf of individuals whose personally identifiable or protected health information may have been compromised. The company continues to assess which records were taken and how many individuals are affected.
Why it matters
A major U.S. health provider suffered a data breach that could expose millions of personal and medical records.
In this story
