Astrana Health 8-K (22 Sep): material cybersecurity incident — social-engineering access; private/confidential data exfiltrated
Astrana Health, Inc. Form 8-K Item 1.05 (date of earliest event 22 September 2026) reports a material cybersecurity incident at subsidiary Astrana Health Management, Inc. Threat actors used social engineering — impersonating company personnel and spoofing the main corporate telephone number — to contact employees and obtain unauthorized access. The company detected and responded, engaged a third-party cybersecurity/forensics firm, notified law enforcement, and is notifying state/federal regulators and payer partners. Remediation includes resetting affected credentials, restricting remote-access tools, rebuilding certain systems from clean backups, and improving monitoring/logging/detection. Investigation determined threat actors accessed and exfiltrated certain private and confidential information; assessment continues on whether patient, employee, credentialed-provider, business/financial, IP, or other data was involved; patient notifications to follow findings. Incident judged material as of 22 Sep 2026 due to potential sensitivity of data; company states it does not currently expect material impact on financial condition or operations. Primary: SEC 8-K; wire: SecurityWeek 24 Sep 2026.
- Product
- Astrana Health Management (Astrana Health, Inc. subsidiary) — healthcare management / claims & billing systems
- Versions
- n/a (incident)
- Exploited in Australia?
- no
- Patch to
- Rotate credentials; restrict remote-access tools; rebuild from clean backups; tighten vishing/callback verification for internal IT requests; monitor for patient/employee notification obligations as forensics completes
Primary: SEC EDGAR — Astrana Health Form 8-K Item 1.05 (22 Sep 2026) · Vendor: Astrana Health — SEC Form 8-K cybersecurity incident · SecurityWeek — Astrana Health data breach (24 Sep 2026)
