STOCK TITAN

Astrana Health reports material cyber incident

Astrana currently expects no material effect on its financial condition or results, while its investigation and assessment of affected information continue.

(Moderate)
(Negative)
Form Type
8-K

Rhea-AI Filing Summary

Astrana Health, Inc. disclosed a cybersecurity incident that it determined was material as of September 22, 2026. Its subsidiary detected unusual activity involving social-engineering attempts to obtain access to company systems. The company says certain private or confidential information on its servers was accessed and/or acquired without authorization, and it is assessing whether patient, employee, provider, business, financial, or intellectual-property information was affected.

Astrana responded by resetting affected credentials, restricting remote access tools, restoring certain systems from clean backups, and enhancing monitoring. Its investigation is ongoing; it has notified law enforcement and is notifying regulators and payer partners. The company cannot yet estimate the incident’s full potential impact, but currently does not expect a material effect on its financial condition or results of operations. Its cybersecurity insurance may cover certain losses.

Positive

  • None.

Negative

  • Cyber incident deemed material as of September 22, 2026.
Item 1.05 Material Cybersecurity Incidents Business
A cybersecurity incident that the company has determined to be material to investors.
Incident materiality determination September 22, 2026 Date as of which Astrana determined the incident was material
Common stock par value $0.001 per share Astrana Health, Inc. common stock
social engineering technical
"a series of social engineering attempts"
Social engineering is the practice of manipulating people into revealing confidential information, granting access, or taking actions that compromise security, often by posing as a trusted person or using urgent, persuasive stories. For investors it matters because these scams can lead to direct financial loss, theft of sensitive corporate data, disrupted operations, or damage to a company’s reputation — similar to a con artist who tricks a business into handing over its keys.
digital forensics technical
"third-party cybersecurity and digital forensics firm"
Digital forensics is the process of collecting, preserving and analyzing electronic evidence from computers, phones or networks to understand what happened during a breach, fraud or other cyber incident. Think of it as a detective examining a crime scene but for digital devices; it helps pinpoint the cause, scope and timeline of an event. Investors care because findings affect a company’s legal exposure, repair costs, regulatory penalties and public trust, all of which can change the value of an investment.
clean backups technical
"restoring certain systems from clean backups"
exfiltrated technical
"may have been accessed, acquired, or exfiltrated"
remote access tools technical
"restricting remote access tools"
Remote access tools are software programs that let a user connect to and control a computer or network from another location, like using a TV remote to change channels on a distant set. They matter to investors because they can boost productivity and lower costs by enabling telework and centralized IT support, but they also raise cybersecurity and compliance risks that can affect a company’s operations, reputation, and financial value if misused or breached.

FAQ

AI-generated questions and answers. How Rhea-AI works. Not financial advice.

What cybersecurity incident did ASTH disclose?

Astrana Health, Inc. said its subsidiary detected unusual activity involving social-engineering attempts to obtain unauthorized access to company systems. The company’s cybersecurity team responded and launched an investigation.

What information may have been accessed in the ASTH incident?

Astrana believes certain private or confidential information on its servers was accessed and/or acquired without authorization. It is assessing whether patient, employee, provider, business, financial, intellectual-property, or other information was affected.

When did ASTH determine the cybersecurity incident was material?

Astrana determined the incident was material as of September 22, 2026, due to the potential confidential and sensitive nature of the data involved.

Does ASTH expect a material financial impact from the incident?

Astrana currently does not expect the incident to have a material effect on its financial condition or results of operations. It cannot yet estimate the full potential impact, including response costs and legal, regulatory, and notification-related matters.

What steps has ASTH taken in response to the incident?

Astrana reset affected credentials, restricted remote access tools, restored certain systems from clean backups, and enhanced monitoring, logging, and detection capabilities. It engaged a cybersecurity and digital forensics firm and notified law enforcement.

Does ASTH have cybersecurity insurance?

Astrana maintains cybersecurity insurance that may cover certain losses associated with the incident. The company stated there can be no assurance that coverage will be sufficient to cover all losses it may incur.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google
Learn about SEC filing dates
0001083446false00010834462026-09-222026-09-22

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, DC 20549

FORM 8-K

CURRENT REPORT

Pursuant to Section 13 or 15(d) of the

Securities Exchange Act of 1934

Date of report (Date of earliest event reported): September 22, 2026

ASTRANA HEALTH, INC.

(Exact Name of Registrant as Specified in Charter)

Delaware

  ​ ​ ​

001-37392

  ​ ​ ​

95-4472349

(State or Other Jurisdiction

(Commission

(I.R.S. Employer

of Incorporation)

File Number)

Identification No.)

1668 S. Garfield Avenue, 2nd Floor, Alhambra, California 91801

(Address of Principal Executive Offices) (Zip Code)

(626) 282-0288

Registrant’s Telephone Number, Including Area Code

(Former Name or Former Address, if Changed Since Last Report)

Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions:

Written communications pursuant to Rule 425 under the Securities Act (17 CFR 230.425)

Soliciting material pursuant to Rule 14a-12 under the Exchange Act (17 CFR 240.14a-12)

Pre-commencement communications pursuant to Rule 14d-2(b) under the Exchange Act (17 CFR 240.14d-2(b))

Pre-commencement communications pursuant to Rule 13e-4(c) under the Exchange Act (17 CFR 240.13e-4(c))

Securities registered pursuant to Section 12(b) of the Act:

Title of each class

Trading symbol(s)

Name of each exchange on which registered

Common Stock, $0.001 par value per share

ASTH

The Nasdaq Stock Market LLC

Indicate by check mark whether the registrant is an emerging growth company as defined in Rule 405 of the Securities Act of 1933 (§230.405 of this chapter) or Rule 12b-2 of the Securities Exchange Act of 1934 (§240.12b-2 of this chapter).

Emerging growth company

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act.

Item 1.05Material Cybersecurity Incident.

Astrana Health, Inc. (the “Company”) recently became aware that its subsidiary Astrana Health Management, Inc. detected unusual activity within its environment.

The incident involved a series of social engineering attempts in which threat actors, impersonating Company personnel and spoofing the Company’s main corporate telephone number, contacted certain employees in an effort to obtain unauthorized access to Company systems. The Company’s cybersecurity team detected and responded to the unauthorized activity, launched an investigation, engaged a leading third-party cybersecurity and digital forensics firm, notified law enforcement, and is notifying state and federal regulators, and payer partners. The Company has also taken remedial measures, including resetting affected credentials, restricting remote access tools, restoring certain systems from clean backups, and enhancing monitoring, logging, and detection capabilities across its environment. The Company’s investigation into the nature and scope of the incident, including the matters described above, remains ongoing.

Based on the current status of the Company’s ongoing investigation, the Company believes that certain private and/or confidential information maintained on the Company’s servers has been accessed and/or acquired without authorization.

The Company continues to assess whether, and to what extent, patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated and continues to evaluate the potential impact of the unauthorized activity. The Company continues to evaluate applicable regulatory and legal notification requirements, and the Company intends to make all required notifications based on its findings, including to impacted patients.

While the investigation is ongoing, the Company has determined that the incident is material as of September 22, 2026, due to the potential confidential and sensitive nature of the data that is involved.

However, the Company is, at this time, unable to estimate the full potential impact of the incident on the Company’s business strategy, operations, financial condition, or results of operations, including remediation and response costs, legal, regulatory and notification-related matters, and possible effects on providers, patients, counterparties and the Company’s reputation, or the impact on the trading price of the Company’s common stock. The Company maintains cybersecurity insurance that may cover certain losses associated with the incident, although there can be no assurance that such coverage will be sufficient to cover all losses the Company may incur. Although the Company is unable to predict the full impact of this incident, the Company currently does not expect that it will have a material effect on the Company’s financial condition and results of operations.

The trust of our valued providers, patients, and payer partners is deeply important to us, and we regret any concern or inconvenience this may cause.

To the extent any information required by Item 1.05(a) of Form 8-K was not determined or was unavailable at the time of this filing, the Company will amend this Current Report on Form 8-K as such information is determined or becomes available.

Forward-Looking Statements

This Current Report on Form 8-K contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended. These statements include words such as “forecast,” “guidance,” “projects,” “estimates,” “anticipates,” “believes,” “expects,” “intends,” “may,” “plans,” “seeks,” “should,” or “will,” or the negative of these words or similar words. Forward-looking statements involve certain risks and uncertainties, and actual results may differ materially from those discussed in each such statement. These forward-looking statements reflect current beliefs, understanding, and expectations regarding the incident, its impact on the Company, and its remediation and investigation. A number of important factors could cause actual results to differ materially from those included within or contemplated by the forward-looking statements, including, but not limited to, the ongoing assessment of the cybersecurity incident and analysis of the scope and details of the incident and the potential discovery of new and additional information related thereto; the Company’s expectations regarding its ability to contain and remediate the cybersecurity incident, including the success of containment and remediation activities to date; any unauthorized release of the Company’s data, including third-party data held by the Company, or the use of any such data for fraudulent purposes; potential loss or destruction of Company data or adverse impacts to the Company’s operations; the impact of the cybersecurity incident on the Company’s relationships with customers, employees, governmental regulators, and other stakeholders; diversion of management’s attention from the Company’s operations to address the cybersecurity incident; legal, regulatory, reputational, and financial risks resulting from the incident or any additional cybersecurity incidents, including those that may arise from any potential regulatory inquiries and/or litigation to which the Company may become subject in connection with the incident; other reputational risk related to the cybersecurity incident; regulatory scrutiny of the cybersecurity incident; risks related to the availability and adequacy of the Company’s insurance coverage for losses and costs associated with the cybersecurity incident; remediation and other additional costs that may be incurred by the Company in connection with the investigation and remediation of the cybersecurity incident; and the factors described in the Company’s filings with the Securities and Exchange Commission, including the Company’s last Annual Report on Form 10-K and subsequent quarterly reports on Form 10-Q. The Company does not undertake any responsibility to update any of these factors or to announce publicly any revisions to any of the forward-looking statements contained in this or any other document, whether as a result of new information, future events, or otherwise, except as may be required by any applicable securities laws.

SIGNATURES

Pursuant to the requirements of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned hereunto duly authorized.

 

ASTRANA HEALTH, INC.

 

 

Date: September 23, 2026

By:

/s/ Brandon K. Sim

 

Name:

Brandon K. Sim

 

Title:

Chief Executive Officer and President

Filing Exhibits & Attachments

3 documents

Keep reading