Astrana latest healthcare tech firm to report data breach to SEC

The healthcare company Astrana warned regulators this week that a recent cyberattack exposed confidential information.
The company filed a report with the Securities and Exchange Commission (SEC) on Tuesday evening about a recent incident in which hackers impersonated Astrana personnel and spoofed the company’s main corporate telephone number.
The hackers contacted employees using the spoofed number and eventually were able to gain access to company servers.
“Based on the current status of the Company’s ongoing investigation, the Company believes that certain private and/or confidential information maintained on the Company’s servers has been accessed and/or acquired without authorization,” Astrana said.
The company did not respond to requests for comment about whether the incident involved ransomware. The report notes that, among several measures taken, the company had to restore “certain systems from clean backups.”
Law enforcement has been notified of the attack alongside other state and federal regulators as well as customers.
The report does not say how many customers were impacted or what kind of information was taken but notes that the “potential confidential and sensitive nature of the data” has made the incident material to the company’s financial position.
Astrana warned that the attack may impact its “business strategy, operations, financial condition… providers, patients, counterparties and the Company’s reputation,” and more.
While cyber insurance may cover some of the costs related to these issues, it is unclear whether it will be enough to make up the losses.
Astrana is one of the largest healthcare tech companies in the U.S., reporting $972.5 million in revenue last quarter through the sale of its operations technology platform to about 20,000 medical providers.
No hacking group has claimed the attack as of Wednesday afternoon, but the incident follows several data breaches involving healthcare technology companies.
Electronic health records company Veradigm recently told the SEC about a data breach involving Social Security numbers and healthcare firms like Nutex, AnMed, Aesto, Baylor Genetics, CareCloud, Paylogix and Boston Scientific have all reported cyberattacks over the last six months.
References in this story
- Astrana Health, Inc. Reports Second Quarter 2026 Results ir.astranahealth.com Company to Host Conference Call on Thursday, August 6, 2026, at 2:30 p.m. PT/5:30 p.m. ET Reports revenue of $972.5 million, up 49%…...
- Electronic health record company says customer data stolen in breach therecord.media Veradigm said access was limited to a specific interface, and did not impact the company’s broader environment such as its networks, servers or databases. The incident did not result in operational disruptions, the…
- Healthcare facilities operator Nutex says patient, employee data stolen in August incident therecord.media Cybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators.
- Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout therecord.media The hackers claimed to have exfiltrated 6 terabytes of data, including highly sensitive health information like records related to sexual assault, mental health, abortions and sexual harassment incidents.
- Health data of more than 9.5 million people leaked from Aesto record system therecord.media The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December.
- Security Update - Baylor Genetics www.baylorgenetics.com
- Electronic health record company CareCloud says 3.7 million people affected by breach therecord.media Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s…
- Employee benefits platform Paylogix says hackers stole financial and health therecord.media The benefits management firm Paylogix told regulators that hackers stole sensitive information on tens of thousands of people from its systems.
- Medical device firm Boston Scientific says cyberattack has disrupted shipment processes therecord.media The company released a statement and filed documents with the Securities and Exchange Commission (SEC) saying a cybersecurity incident was discovered on Tuesday.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
- jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51



