Astrana Health, a California-based physician-centric healthcare management company, has disclosed a data breach involving its subsidiary Astrana Health Management. In a filing with the US Securities and Exchange Commission, the company said attackers used social engineering tactics, including impersonating Astrana personnel and spoofing its main phone number, to contact employees and gain access to its servers.

Astrana Health provides back-office services for physician practices, including claims processing and billing, meaning the compromised systems may have touched sensitive patient and financial data across its provider network.

Response and Containment

After detecting the intrusion, Astrana Health engaged a third-party cybersecurity firm, notified relevant authorities and business partners, and launched an investigation. Remediation steps included rotating credentials, restricting remote access tools, rebuilding affected systems from clean backups, and enhancing monitoring, logging, and detection capabilities.

The investigation confirmed that threat actors accessed and exfiltrated certain private and confidential information from company servers. Astrana Health said it is still assessing whether patient, employee, credentialed provider, confidential business and financial information, or intellectual property was accessed or acquired, and continues to evaluate the scope of the unauthorized activity.

Material but Not Financially Disruptive

Astrana Health told the SEC the incident is considered material due to the potential sensitivity of the data involved, but does not expect it to materially affect the company’s financial condition or operations.

The company has not named the threat actor responsible, and no known ransomware or extortion group has publicly claimed responsibility for the attack.

Why It Matters

The incident underscores the continued effectiveness of social engineering and phone number spoofing as initial access vectors, even against organizations handling regulated healthcare data. Security teams supporting healthcare and back-office service providers should reinforce employee verification procedures for internal communications and monitor for impersonation attempts targeting help desks and remote access channels.