← Astrana Health

2026 Astrana Health — social-engineering intrusion; private/confidential data exfiltrated (SEC 8-K)

2026 Unknown records affected Share on X

Data compromised

Per SEC 8-K: certain private and/or confidential information on company servers accessed and/or acquired. Company still assessing whether patient, employee, credentialed provider, business/financial, IP, or other data was involved. Individual census unpublished.

Technical writeup

Verified Astrana Health, Inc. Form 8-K (Item 1.05) — filed ~September 23, 2026; materiality determined September 22, 2026. Subsidiary Astrana Health Management detected unusual activity after threat actors impersonated company personnel and spoofed the main corporate telephone number to contact employees and obtain unauthorized access. Company engaged a third-party forensics firm, notified law enforcement, and is notifying state/federal regulators and payer partners. Remediation: credential resets, restricted remote-access tools, restore of certain systems from clean backups, enhanced monitoring/logging/detection. Investigation ongoing on whether patient, employee, provider, confidential business/financial, IP, or other information was exfiltrated; company intends patient notifications if required. No named ransomware claim reported in coverage. Headcount unpublished — recordsAffected 0; companyConfirmed true.

Root cause

Threat actors spoofed Astrana’s main corporate phone number and impersonated personnel to socially engineer employees into granting system access (SEC Form 8-K Item 1.05)

References