The news
Astrana Health (ASTH), a California-based healthcare company, told the U.S. Securities and Exchange Commission on September 23, 2026, that an Astrana Health cyberattack involved callers impersonating staff and spoofing its main phone number. The company believes confidential data was accessed or taken.
The disclosure came in a Form 8-K under Item 1.05, the section public companies use to report material cybersecurity incidents. According to the filing, the company's subsidiary Astrana Health Management, Inc. detected unusual activity within its environment. Threat actors ran a series of social engineering attempts, contacting certain employees while posing as company personnel and displaying Astrana's own corporate number in an effort to gain access to its systems. Social engineering refers to tricking people, rather than breaking software, to get access.
Astrana said it believes certain private or confidential information on its servers was accessed or acquired without authorization. The filing lists potentially affected categories as patient, employee, credentialed provider, confidential business and financial information, intellectual property or other information. The company did not say how many people may be affected, whether ransomware was involved or whether any group has claimed responsibility.
In response, Astrana said it engaged outside cybersecurity experts, notified law enforcement, reset affected credentials, restricted remote access tools, restored certain systems from clean backups and increased monitoring. It said it is notifying state and federal regulators and payer partners. The investigation is continuing and the full scope has not been determined.
The company said it determined the incident was material as of September 22, 2026, because of the potentially confidential and sensitive nature of the data. It said it cannot yet estimate the full impact, but currently does not expect the incident to have a material effect on its financial condition and results of operations. It noted it carries cybersecurity insurance. Chief Executive Brandon K. Sim signed the filing. Stock research site StockStory reported that Astrana shares fell 5.5% in afternoon trading on September 23, 2026, after the disclosure.
The numbers
- Date incident deemed material
- September 22, 2026
- Form 8-K filing date
- September 23, 2026
- Reported share move after disclosure
- Down 5.5% in afternoon trading on September 23, 2026 (per StockStory)
Why CEOs should care
For CISOs, the method deserves attention because it is cheap and repeatable. Caller ID spoofing lets an attacker make a call appear to come from a trusted internal number, and staff are trained to trust their own company's line. Help desks and employees who reset passwords, enroll devices or approve remote access should verify requests by calling back a number from an internal directory, and should never grant access based on the caller ID alone. Astrana's decision to restrict remote access tools also signals where attackers often go next.
For CFOs and general counsels, the filing illustrates how the SEC's materiality test works in practice. Astrana deemed the incident material because of the sensitivity of the data, while saying it does not currently expect a material financial effect. Companies should document both judgments separately and be ready to explain to investors why an incident is material even when near-term costs look manageable. Legal teams should also confirm whether their cyber insurance covers social engineering losses, which some policies treat differently.
For boards of healthcare and services firms, the list of possibly affected data, from patient records to credentialed provider information, points to regulatory exposure beyond the SEC. Ask management how quickly it can determine which individuals are affected and which health privacy and state notification rules apply.
The bigger picture
Astrana's case shows why voice-based social engineering is hard to defend against: it targets people and processes rather than software flaws. An attacker who can convincingly impersonate an employee or the help desk may be able to sidestep technical defenses, then use legitimate remote access tools to move around.
The case also adds to a run of healthcare breach disclosures. The Record, a cybersecurity news outlet, reported on September 24, 2026, that electronic health records company Veradigm recently told the SEC about a data breach and that several other healthcare firms have reported cyberattacks over the last six months. Astrana filed its Item 1.05 report, the SEC's disclosure requirement for material cybersecurity incidents, one day after its materiality determination and before it could say how many people were affected, illustrating the trade-off between early disclosure and incomplete facts.
What’s next
Watch for an amended 8-K or later filings with more detail on what data was taken and how many people are affected, any claim by a hacking group, and notifications to patients and providers. Investors should also look for any change to the company's financial outlook if remediation or legal costs grow. Healthcare organizations should test their help desk verification procedures against spoofed internal calls.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





