Astrana Health has confirmed a data breach after threat actors impersonated company personnel and spoofed its main corporate telephone number as part of a social engineering attack that ultimately provided unauthorized access to company systems.
The healthcare company disclosed the incident in a filing with the U.S. Securities and Exchange Commission, saying its Astrana Health Management subsidiary detected unusual activity within its environment.
Astrana now believes attackers accessed or acquired private and confidential information maintained on its servers. The company is still determining whether patient, employee and healthcare provider information was among the data affected.
The company determined the incident was material on September 22, 2026 because of the potentially confidential and sensitive nature of the information involved.
Attackers impersonated Astrana personnel by phone
Astrana’s disclosure provides an unusually clear description of the social engineering technique used to gain access.
According to the company, threat actors conducted a series of social engineering attempts in which they impersonated Astrana personnel and spoofed the company’s main corporate telephone number while contacting employees.
The attackers used those calls in an effort to obtain unauthorized access to Astrana systems.
Astrana did not disclose exactly what information the attackers requested from employees, whether credentials or multifactor authentication were compromised, which remote access tools were involved, or how long the attackers maintained access.
The company also has not attributed the attack to a specific threat actor or ransomware operation.
Private and confidential information accessed
Astrana’s investigation has established that certain private or confidential information stored on company servers was accessed or acquired without authorization.
The exact data involved remains under investigation.
Astrana said it is determining whether patient information, employee information, credentialed provider data, confidential business and financial information, intellectual property or other information was accessed, acquired or exfiltrated.
The company has not disclosed how many people may be affected.
Astrana also has not yet established which specific patient data types may have been exposed, meaning there is currently no confirmation that Social Security numbers, medical records, diagnoses, insurance information or other particular categories of protected health information were stolen.
The company said it continues to evaluate its legal and regulatory notification requirements and intends to notify affected patients when required based on the results of its investigation.
Systems restored from clean backups
Astrana’s response extended beyond resetting potentially compromised accounts.
After detecting the unauthorized activity, the company’s cybersecurity team launched an investigation and brought in a third-party cybersecurity and digital forensics firm.
Astrana reset affected credentials, restricted remote access tools and restored certain systems from clean backups. It also enhanced monitoring, logging and detection capabilities across its environment.
The company has notified law enforcement and is notifying state and federal regulators as well as payer partners.
Astrana did not say whether ransomware was deployed or files were encrypted. Restoring systems from clean backups can form part of the response to numerous types of compromises and does not by itself establish that ransomware was involved.
Incident declared material
Astrana determined that the incident met the threshold for a material cybersecurity disclosure because of the potentially confidential and sensitive nature of the information involved.
The company said it cannot yet estimate the full impact on its business strategy, operations, financial condition or results.
Potential costs could include incident response and remediation, regulatory and legal expenses, notification obligations and effects on patients, healthcare providers, counterparties and Astrana’s reputation.
Astrana maintains cybersecurity insurance that may cover some losses associated with the incident, although the company cautioned that coverage may not be sufficient to cover every loss.
Despite classifying the breach as material, Astrana currently does not expect it to have a material effect on its overall financial condition or results of operations.
Astrana supports thousands of healthcare providers
Astrana Health operates a technology-powered healthcare platform focused on value-based care, supporting physicians and healthcare organizations across the United States.
The company’s operations include healthcare management and administrative services that place it within an ecosystem involving patients, providers, payer partners and other healthcare organizations.
That makes the scope of the information accessed particularly important. Astrana’s investigation is still determining whether the breach extended into patient or credentialed provider information and what categories of data were actually taken.
The company has previously acknowledged experiencing cyber incidents, but said in its 2025 annual report that it had not experienced a cybersecurity breach that materially affected its business through the date of that filing.
Phone spoofing highlights social engineering risk
The attack demonstrates how compromising an organization does not always require exploiting a software vulnerability.
Caller ID information can be manipulated to make a call appear to originate from a trusted number. When combined with knowledge of an organization’s employees, internal processes or terminology, the technique can make an impersonation attempt significantly more convincing.
In Astrana’s case, the attackers allegedly combined personnel impersonation with spoofing of the company’s primary corporate number before obtaining unauthorized access.
The incident also illustrates why organizations increasingly treat identity verification as separate from the phone number or caller information displayed to an employee. A familiar corporate number does not establish that the caller actually belongs to the organization.
Full breach scope remains under investigation
Astrana has confirmed unauthorized access and the acquisition of private or confidential information, but several important questions remain unanswered.
The company has not disclosed the number of affected patients, employees or providers, the exact information stolen, the duration of the intrusion or whether the attackers attempted to extort the company.
No threat actor has publicly been attributed to the incident.
Astrana said its investigation remains ongoing and that it will make required notifications, including to affected patients, as additional findings establish who and what was impacted.










