Astrana Health Notifies SEC About Social Engineering Incident
Astrana Health, a managed services organization that helps healthcare providers deliver value-based, coordinated care to patients, has notified the U.S. Securities and Exchange Commission (SEC) about a material cybersecurity incident that exposed patient, employee, and provider information.
According to the Form 8-K filing, Astrana Health subsidiary Astrana Health Management identified unusual activity within its information technology environment. The forensic investigation found that threat actors had conducted a series of social engineering attempts against employees. The threat actors impersonated company personnel and spoofed the company’s main telephone number and tricked employees into providing them with access to company systems.
The company engaged a third-party cybersecurity and digital forensics firm to assist with the investigation and notified law enforcement. Steps have been taken to bolster security to prevent similar incidents in the future, including resetting all affected credentials, restricting the use of remote access tools, restoring systems from clean backups, and enhancing monitoring.
The investigation and data review are ongoing; however, Astrana Health believes that certain private and/or confidential information stored on the affected servers has been accessed and/or acquired. Data is being reviewed to determine what patient, employee, credentialed provider, intellectual property, and confidential business and financial information may be involved. On September 22, 2026, the company determined that it constitutes a material cybersecurity incident due to the confidential and sensitive nature of the data involved.
At the time of issuing the Form 8-K filing, Astrana Health was unable to estimate the full impact of the incident on the company’s business strategy, operations, financial condition, or results of operations. The company holds a cyber insurance policy that may cover certain losses associated with the incident. Currently, no ransomware or cybercriminal group appears to have claimed responsibility for the cyberattack.



