Astrana Health, a California-based physician-centric healthcare management company, reported that private and confidential information was stolen from its servers. The breach occurred after employees were targeted in a social engineering attack, where hackers impersonated company personnel and spoofed its main phone number to gain access.
The incident involved Astrana Health Management, a subsidiary of Astrana Health, as detailed in a filing with the US Securities and Exchange Commission (SEC). Upon detecting the attack, the company engaged a third-party cybersecurity firm, notified authorities and partners, and launched an investigation. Response measures included rotating credentials, restricting remote access, rebuilding systems from backups, and improving monitoring and detection capabilities.
The investigation confirmed that threat actors accessed and exfiltrated certain private and confidential information. Astrana Health is still assessing the full extent of the breach, specifically whether patient, employee, credentialed provider, confidential business and financial information, or intellectual property was compromised. The company stated the incident is material due to the sensitive nature of the data involved, but does not expect it to impact its financial condition or operations.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Astrana Health, a healthcare management company, disclosed a data breach where private and confidential information was exfiltrated from its servers following a social engineering attack on employees. The company is assessing the extent to which patient, employee, and business data may have been accessed.