Astrana Health Tells SEC Hack Exposed Sensitive Data
Astrana Health notified the SEC of a data breach caused by a social engineering attack, potentially exposing patient, provider, and corporate data. The company is investigating and has taken remedial actions. Astrana, with 2025 revenue of $3.2B, stated the incident is material but does not expect it to affect its financial condition or operations. The company has cyber insurance but cannot guarantee it will cover all losses.
How this was made
The 30-second read
Why it matters
The filing is the first public disclosure of the incident, making it a primary source of new information for investors.
Market read
First‑report of a material cyber breach at a mid‑cap healthcare services firm; may affect stock perception and sector risk assessment.
What to watch
Potential regulatory fines and reputational damage could affect partner contracts.
Background
Astrana Health disclosed a material cyber‑security breach to the SEC, describing the attack, data types potentially exposed, and remediation steps.
Market effects
Highlights cybersecurity risk for healthcare services firms.
May raise scrutiny of US healthcare providers with similar data practices.
Adds to broader concerns about social‑engineering attacks on listed companies.
Counterpoint
The breach may be over‑stated; insurance coverage could limit financial fallout.
Key entities
- companyAstrana Health
California‑based managed services organization in the healthcare sector.




