Astrana Health discloses server breach to SEC after employee-impersonation attack
Astrana Health, a California-based healthcare management company, disclosed in an SEC filing that attackers impersonated staff and spoofed its main corporate phone number to trick employees into granting access to its servers12. The company serves roughly 20,000 medical providers and posted $972.5 million in quarterly revenue2. It says it does not yet know the full scope of what was taken, but believes private and confidential information, potentially including patient, employee, provider and financial records, was accessed and exfiltrated1.
No ransomware or extortion group has claimed responsibility, and Astrana has not said whether ransomware was involved12. The company has restored affected systems from clean backups, rotated credentials, restricted remote access tools and notified law enforcement and regulators1. It filed an 8-K report calling the breach material due to the sensitivity of the data, while saying it does not expect a material hit to its finances12.
Why it matters: social engineering keeps beating technical defences, and Astrana becomes the latest in a lengthening string of healthcare-sector breaches this year, a sector where stolen records carry an outsized cost regardless of whether ransomware ends up being involved.