
Astrana Health, a California-based technology-powered healthcare company that supports thousands of physicians through its management services organization, disclosed a cybersecurity incident this week.
In a Form 8-K filed with the Securities and Exchange Commission on September 23, 2026, the company reported that its subsidiary, Astrana Health Management, detected unusual activity after attackers used social engineering to gain unauthorized access to company systems.
According to the filing, threat actors impersonated company personnel and spoofed Astrana’s main corporate telephone number. They contacted certain employees in a series of attempts designed to obtain access to internal systems. Once inside, the attackers accessed and acquired certain private and confidential information stored on the company’s servers.
Astrana’s cybersecurity team detected the activity, launched an investigation and began alerting state and federal regulators as well as payer partners.
The company also took remedial steps that included resetting affected credentials, restricting remote access tools and strengthening monitoring and detection capabilities.
The investigation remains ongoing and Astrana stated it is still determining whether, and to what extent, patient information, employee data, credentialed provider records, confidential business or financial details, or intellectual property were accessed or removed.
The company classified the incident as material as of September 22, 2026, citing the potentially sensitive nature of the data involved. It has indicated it does not currently expect a material impact on its overall financial condition or operations.
As of the latest public statements, Astrana has not released the number of individuals affected or a full inventory of the specific data elements compromised. The company said it will issue required notifications, including to impacted patients, once the investigation is complete.
Healthcare data breaches carry particular risks. Exposed personal or medical information can lead to identity theft and long-term privacy harms. Individuals who later receive notice that their information was involved should monitor accounts carefull and document any related expenses or issues.
If you believe your personal or medical information may have been affected by the Astrana Health incident, contact the data breach lawyers at The Lyon Firm for a free consultation to discuss your legal options and potential recovery.
Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there: