Astrana latest healthcare tech firm to report data breach to SEC
The healthcare company Astrana warned regulators this week that a recent cyberattack exposed confidential information.
The company filed a report with the Securities and Exchange Commission (SEC) on Tuesday evening about a recent incident in which hackers impersonated Astrana personnel and spoofed the company’s main corporate telephone number.
The hackers contacted employees using the spoofed number and eventually were able to gain access to company servers.
“Based on the current status of the Company’s ongoing investigation, the Company believes that certain private and/or confidential information maintained on the Company’s servers has been accessed and/or acquired without authorization,” Astrana said.
The company did not respond to requests for comment about whether the incident involved ransomware. The report notes that, among several measures taken, the company had to restore “certain systems from clean backups.”
Law enforcement has been notified of the attack alongside other state and federal regulators as well as customers.
The report does not say how many customers were impacted or what kind of information was taken but notes that the “potential confidential and sensitive nature of the data” has made the incident material to the company’s financial position.
Astrana warned that the attack may impact its “business strategy, operations, financial condition… providers, patients, counterparties and the Company’s reputation,” and more.
While cyber insurance may cover some of the costs related to these issues, it is unclear whether it will be enough to make up the losses.
Astrana is one of the largest healthcare tech companies in the U.S., reporting $972.5 million in revenue last quarter through the sale of its operations technology platform to about 20,000 medical providers.
No hacking group has claimed the attack as of Wednesday afternoon, but the incident follows several data breaches involving healthcare technology companies.
Electronic health records company Veradigm recently told the SEC about a data breach involving Social Security numbers and healthcare firms like Nutex, AnMed, Aesto, Baylor Genetics, CareCloud, Paylogix and Boston Scientific have all reported cyberattacks over the last six months.
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



