Astrana Health, Inc., a Nasdaq-listed, Alhambra, California-based value-based care and physician-network operator, has disclosed in a filing with the Securities and Exchange Commission that attackers impersonated company personnel — even spoofing the company’s own main phone number — to trick employees into handing over network access. Astrana says it intends to notify affected patients, but no notice has gone out yet.
Astrana Health, Inc. (Nasdaq: ASTH), a value-based care company that operates physician networks across California and other states, filed a Form 8-K with the SEC on September 23, 2026, disclosing a “material cybersecurity incident” at its subsidiary, Astrana Health Management, Inc. According to the filing, the company determined the incident was material on September 22, 2026 — the day before it filed. Astrana says the attack used “vishing,” a form of voice-based social engineering in which attackers impersonated company personnel and spoofed Astrana’s own main corporate phone number to convince employees to hand over access to internal systems. The company states that certain private and confidential information on its servers was accessed or acquired without authorization, and that it intends to notify impacted patients.
Source: Astrana Health, Inc. Form 8-K, Item 1.05 Material Cybersecurity Incident, filed with the SEC on 09/23/2026 (date of earliest event 09/22/2026).
What Information May Be at Risk
Astrana has not yet determined what specific information was affected. The company’s own filing states that it is still assessing whether patient information, employee information, credentialed-provider information, and confidential business and financial information were involved. No population figure or confirmed data-type list has been released, and none is available from any other source at this time.
Why a “Vishing” Attack Is Worth Taking Seriously
Vishing — voice phishing — is a social-engineering tactic where attackers call employees directly, often posing as IT support or company leadership, to talk their way into system access. Astrana’s own disclosure that attackers spoofed the company’s actual main phone number is notable: it suggests a targeted, well-researched attack rather than a random phishing attempt, and it raises questions about whether the company’s help-desk identity-verification procedures were adequate to catch a caller using a spoofed internal number.
What We Know — and What We Don’t
This is an unusually fast corporate disclosure — Astrana went from determining the incident was material to filing with the SEC in a single day. That speaks well of the company’s securities-disclosure process, but it’s a different clock from the one that matters to patients and employees: as of this writing, no notice has been sent to affected individuals, and no filing has been made with the California Attorney General or any other state regulator. We’re opening an investigation now, at the earliest point this case is public, and will update this post as more facts become available.
Who Astrana Health Serves
Astrana Health operates physician networks and provides value-based care management across California and other states, working with a large base of patients through its affiliated medical groups and independent practice associations, as well as with credentialed providers who participate in those networks. If this incident is confirmed to involve patient or provider data, the affected population could be substantial given the scale of Astrana’s network.
Why We’re Investigating Now, Before Any Notice Goes Out
Astrana’s own SEC filing states that it intends to notify affected patients. That notice could still be weeks or months away — the company has said it is still assessing what data was involved. Emery | Reddy is opening an investigation now so that affected patients, employees, and providers are ready to act as soon as more information becomes available, rather than starting from scratch once a notice letter arrives.
What You Can Do Now
- If you’re a patient in an Astrana-affiliated medical group or IPA, or a current or former Astrana employee, keep an eye on your mail and email for a notice letter
- Watch for phishing calls or texts referencing Astrana Health or your medical provider, especially anyone claiming to be from Astrana’s IT or billing department
- Contact us to be included in our investigation, so we can reach you directly if and when more information is confirmed
Do You Have Legal Options?
Companies that manage patient and provider data through physician networks have a legal duty to secure that information, including training staff to resist social-engineering attacks like vishing. If this incident is confirmed to involve your information, you may have legal options.
If you’re an Astrana Health patient, employee, or credentialed provider, contact Emery | Reddy today to be included in our investigation.
FAQ
Has Astrana Health confirmed what information was exposed?
No. Astrana’s own SEC filing states the company is still assessing whether patient, employee, credentialed-provider, business, and financial information were affected. No confirmed list of exposed data exists yet.
How many people are affected?
No population figure has been released. Astrana’s filing states the company is unable to estimate the scope of the incident at this time.
Has Astrana sent notice to patients or employees yet?
Not as of this writing. Astrana’s SEC filing states the company intends to notify impacted patients, but no notice has gone out and no filing has been made with any state regulator yet.
What is “vishing”?
Vishing is voice-based phishing — attackers call employees, often posing as IT staff or leadership, to trick them into providing system access or credentials. Astrana’s disclosure states the attackers spoofed the company’s own main phone number as part of the scheme.
Why are you writing about this before Astrana has sent any notice?
Astrana’s own SEC filing already confirms the incident occurred and states the company intends to notify patients. We’re opening our investigation now so that affected patients, employees, and providers are prepared to act quickly once more details are confirmed.
Do I have a legal claim?
Companies that manage patient and provider data have a legal duty to secure it, including training employees to resist social-engineering attacks. If you’re an Astrana Health patient, employee, or credentialed provider, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.