Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-30 · updated: 2026-09-30 · tags: [incident, healthcare] · confidence: high · severity: medium · affected_sectors: [healthcare] · au_impact: true

Astrana Health, a managed services organisation supporting healthcare providers, notified the US Securities and Exchange Commission of a material cybersecurity incident exposing patient, employee and provider information. According to the Form 8-K filing, subsidiary Astrana Health Management identified unusual activity in its IT environment, and the forensic investigation found that threat actors had conducted a series of social engineering attempts against employees, impersonating company personnel and spoofing the company's main telephone number to deceive them. The company engaged a third-party cybersecurity and digital forensics firm, notified law enforcement, and took remediation steps including resetting all affected credentials, restricting the use of remote access tools, restoring systems from clean backups and enhancing monitoring. The investigation and data review are ongoing, but the company believes certain private or confidential information stored on the affected servers has been accessed. The SEC-notification route is the notable element: a materiality-filed 8-K with an unreleased record count is now the standard first disclosure for US healthcare entities, which means the operational facts arrive through an investor filing before affected individuals are told.

Attribute Detail
Sector Healthcare
Date 2026-09-30
Source HIPAA Journal
Reliability Tier 3