Astrana Health reports material cyber incident
Astrana currently expects no material effect on its financial condition or results, while its investigation and assessment of affected information continue.
Rhea-AI Filing Summary
Astrana Health, Inc. disclosed a cybersecurity incident that it determined was material as of September 22, 2026. Its subsidiary detected unusual activity involving social-engineering attempts to obtain access to company systems. The company says certain private or confidential information on its servers was accessed and/or acquired without authorization, and it is assessing whether patient, employee, provider, business, financial, or intellectual-property information was affected.
Astrana responded by resetting affected credentials, restricting remote access tools, restoring certain systems from clean backups, and enhancing monitoring. Its investigation is ongoing; it has notified law enforcement and is notifying regulators and payer partners. The company cannot yet estimate the incident’s full potential impact, but currently does not expect a material effect on its financial condition or results of operations. Its cybersecurity insurance may cover certain losses.
Positive
- None.
Negative
- Cyber incident deemed material as of September 22, 2026.
8-K Event Classification
Key Figures
Key Terms
social engineering technical
digital forensics technical
clean backups technical
exfiltrated technical
remote access tools technical
FAQ
AI-generated questions and answers. How Rhea-AI works. Not financial advice.
What cybersecurity incident did ASTH disclose?
What information may have been accessed in the ASTH incident?
When did ASTH determine the cybersecurity incident was material?
Does ASTH expect a material financial impact from the incident?
What steps has ASTH taken in response to the incident?
Does ASTH have cybersecurity insurance?
AI-generated analysis. How Rhea-AI works. Not financial advice.