Material Cybersecurity Incident Disclosure |
Sep. 22, 2026 |
|---|---|
| Material Cybersecurity Incident [Line Items] | |
| Material Cybersecurity Incident Nature [Text Block] | Astrana Health, Inc. (the “Company”) recently became aware that its subsidiary Astrana Health Management, Inc. detected unusual activity within its environment. |
| Material Cybersecurity Incident Scope [Text Block] | Astrana Health, Inc. (the “Company”) recently became aware that its subsidiary Astrana Health Management, Inc. detected unusual activity within its environment. The incident involved a series of social engineering attempts in which threat actors, impersonating Company personnel and spoofing the Company’s main corporate telephone number, contacted certain employees in an effort to obtain unauthorized access to Company systems. The Company’s cybersecurity team detected and responded to the unauthorized activity, launched an investigation, engaged a leading third-party cybersecurity and digital forensics firm, notified law enforcement, and is notifying state and federal regulators, and payer partners. The Company has also taken remedial measures, including resetting affected credentials, restricting remote access tools, restoring certain systems from clean backups, and enhancing monitoring, logging, and detection capabilities across its environment. The Company’s investigation into the nature and scope of the incident, including the matters described above, remains ongoing. Based on the current status of the Company’s ongoing investigation, the Company believes that certain private and/or confidential information maintained on the Company’s servers has been accessed and/or acquired without authorization. The Company continues to assess whether, and to what extent, patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated and continues to evaluate the potential impact of the unauthorized activity. The Company continues to evaluate applicable regulatory and legal notification requirements, and the Company intends to make all required notifications based on its findings, including to impacted patients. |
| Material Cybersecurity Incident Timing [Text Block] | September 22, 2026 |
| Material Cybersecurity Incident Information Not Available or Undetermined [Text Block] | However, the Company is, at this time, unable to estimate the full potential impact of the incident on the Company’s business strategy, operations, financial condition, or results of operations, including remediation and response costs, legal, regulatory and notification-related matters, and possible effects on providers, patients, counterparties and the Company’s reputation, or the impact on the trading price of the Company’s common stock. The Company maintains cybersecurity insurance that may cover certain losses associated with the incident, although there can be no assurance that such coverage will be sufficient to cover all losses the Company may incur. Although the Company is unable to predict the full impact of this incident, the Company currently does not expect that it will have a material effect on the Company’s financial condition and results of operations. |