Overview
- Primary disclosure
- September 23, 2026 SEC filing
- September 22 means
- Materiality determination, not attack date
- Current stage
- Investigation; individual exposure uncertain
Astrana Health's September 23, 2026 SEC filing reports a cybersecurity incident, but it does not establish a patient's individual exposure, specific stolen identifiers, or entitlement to compensation. Attorneys are investigating possible claims and recruiting people who believe they may be affected. This is not a verified filed class action, certified class, or settlement. The company's belief that certain private or confidential information was accessed or acquired is qualified by an ongoing investigation. Original SEC filing Recruiting page
The distinction matters if you are a patient, employee, or provider. Your relationship to Astrana may explain why records could exist in its systems, but it does not prove those records were involved. Available action is information gathering and legal review, not applying for an established payment.
Who the parties are
Astrana Health, Inc. is a California-based healthcare company supporting providers with technology and management services. Its public website describes patient access to primary and specialty care. Patients can interact with care providers while administrative work occurs elsewhere, so the management-company name may differ from the name on a clinic sign. The corporate services explain the potential connection, not which specific clinic's records were affected. Company website Company and subsidiary context
Astrana Health Management, Inc. is the subsidiary that the filing says detected unusual activity. The recruiting sources describe its administrative and back-office role for providers. Levi & Korsinsky, LLP is investigating and inviting patients to contact it. The Securities and Exchange Commission, or SEC, receives public-company disclosures; receiving this filing does not mean the agency prosecuted a privacy case. No named plaintiff, court, or settlement administrator was verified. SEC filing Firm investigation
What happened
The filing says threat actors impersonated company personnel and spoofed its main corporate telephone number while contacting certain employees to seek unauthorized system access. Social engineering means manipulating people rather than relying only on a software vulnerability. Phone spoofing makes a call appear to come from another number. These descriptions do not identify the attackers or prove which individual employee action enabled access. SEC filing
Astrana determined that the incident was material as of September 22, 2026, because of the potentially sensitive and confidential data involved. It filed the report on September 23. September 22 is not a verified intrusion or detection date; neither date is supplied in the filing. Astrana said it believes certain information was accessed or acquired without authorization while continuing to evaluate what information, and whose records, may have been accessed, acquired, or exfiltrated. SEC filing
What each side says
Astrana says it engaged outside cybersecurity and digital-forensics experts, notified law enforcement, and was notifying regulators and payer partners. Its reported measures include resetting affected credentials, restricting remote-access tools, restoring certain systems from clean backups, and improving monitoring. It intends to make required notifications, including to impacted patients, based on its findings. Notification plans are not confirmation that every patient was affected. SEC filing
The company could not estimate the full impact but did not then expect a material effect on its financial condition and operating results. That financial expectation does not establish absence of individual privacy harm. ClassAction.org describes possible compensation and security changes if litigation is filed and succeeds; Levi & Korsinsky is assessing potential rights. These are recruiting positions, not allegations from a verified complaint. No plaintiff testimony, defense pleading, or regulator finding was verified. SEC filing Recruiting page Firm investigation
What the court has and has not decided
The reviewed sources supply no verified case number, court, certification order, judgment, or approved settlement. This article does not claim an exhaustive search of all possible proceedings. It reports the supported investigation stage and does not convert a securities disclosure into a court finding.
A complaint would present allegations for adjudication. Certification would separately determine whether a case can proceed for a defined group. Under federal Rule 23, class certification and class-settlement approval require judicial decisions. An intake form, corporate notice, or SEC filing provides none of those decisions and does not establish liability. Rule 23
Who may qualify
- Patients who reasonably believe information held through an Astrana-supported provider may have been involved can ask for review; the filing does not confirm that all patients were affected.
- Employees who believe their information may have been involved can inquire through the ClassAction.org investigation; no employee-wide exposure is established.
- Credentialed providers who believe their information may have been involved can inquire; provider affiliation is not proof that records were accessed.
- Any later individual incident notice may help clarify your records. Retain it, but do not treat a generic company disclosure as confirmation about you.
- No court-defined class, geographic exclusions, affected-service dates, or formal proof rules were verified. An attorney must assess your facts and applicable law.
ClassAction.org seeks people who believe information may have been affected, including Astrana employees, credentialed providers, and patients. Levi & Korsinsky specifically invites current or former patients of providers using Astrana's services. Those descriptions concern recruitment, not verified exposure for an entire patient, employee, or provider group. Recruiting page Firm investigation
The filing evaluates patient, employee, provider, business, financial, intellectual-property, and other information without confirming specific categories for any individual. Do not assume Social Security numbers, diagnoses, or insurance details were stolen. No court-defined geography, service-date range, exclusions, or mandatory proof requirements were verified. A later personal notice may clarify your records; affiliation alone is insufficient. SEC filing
What affected readers can do now
Keep any individual notice and relevant employment, provider, or benefits correspondence. Ask Astrana or your provider about records through contact information you already trust. Do not send medical records or identifiers in response to an unexpected message. The FTC recommends verifying requests using a known company channel rather than information supplied by an unsolicited caller. FTC medical guidance
Review explanation-of-benefits statements for services you did not receive. An explanation of benefits summarizes care, costs, and coverage; it is not necessarily a bill. If you identify medical-record errors, follow the provider's correction process and preserve correspondence. Free credit freezes are available through all three bureaus even without confirmed exposure; an initial fraud alert starts with one. Credit protection does not replace reviewing medical records. FTC medical guidance FTC credit guidance
For legal review, use the cited investigation pages and check who receives information. ClassAction.org says contact costs nothing and creates no obligation to act. Keep receipts and a dated time log for actual consequences. Intake does not establish representation, file litigation, or suspend a legal deadline.
What you could receive
Protect and review your records
FTC guidance supports checking benefits statements and considering free credit freezes. These public protections are not benefits awarded by Astrana or proof that your data was affected.
Request an investigation review
The live ClassAction.org and Levi & Korsinsky pages invite potentially affected people. They describe no-cost contact or participation, not automatic representation or compensation.
No cash claim to submit
Recruiters describe possible relief only if a case proceeds successfully. No payment amount, proof schedule, combination rule, or settlement benefit election is established.
No payment, settlement fund, reimbursement terms, or patient monitoring enrollment is established in the reviewed filing. It mentions cybersecurity insurance that may cover some company losses and warns that coverage may be insufficient. That is not a patient insurance benefit or a direct compensation program. SEC filing
Recruiters describe possible monetary relief or security improvements only conditionally. No approved benefit options, caps, proof rules, or combination rules exist in this source set. Public protective tools and a legal consultation are available activities, not settlement awards. Documenting a loss helps explain what happened to you but does not guarantee recovery. Recruiting page
Important dates and rights
The verified dates are September 22 for materiality and September 23 for filing. The original report says Astrana will amend it as required incident information becomes available. Its current filing index was also checked, but no timetable for individual notices or investigation completion was established. SEC filing Company filing index
No claim, objection, exclusion, or hearing deadline was verified. Do not assume an inquiry extends an individual limitation period. No release of legal claims is described by the recruiting materials, but any representation agreement must be reviewed separately. If a qualifying class settlement later appears, its official notice would explain binding effects, applicable exclusion rights, and objections. No such process is established here. Rule 23
Definitions
A Form 8-K is a public company's current report to the SEC. Materiality here concerns the significance of the cybersecurity incident for that disclosure, not a judicial finding that a particular patient suffered harm. Digital forensics examines electronic evidence; exfiltration means moving data out of a system. The filing distinguishes evaluating those possibilities from confirming every information category. SEC filing
A credentialed provider is a healthcare professional whose qualifications are checked for participation. An investigation assesses facts and potential claims; a filed case asks a court to decide them. Certification concerns group treatment, and a settlement is an agreement resolving claims. Medical identity theft means someone uses another person's information to obtain care or insurance payments, not simply that an incident occurred. Rule 23 FTC medical guidance
What happens next
Astrana's reported next steps are continued assessment and required notifications based on the findings. Lawyers may evaluate whether claims can proceed, but no filing date, class definition, or outcome is promised. A later company notice could identify individual data; a verified complaint would add allegations; a court order would establish what the court actually decided. Treat those documents as different kinds of evidence. SEC filing Recruiting page
Continue documenting real concerns without attributing every unfamiliar bill or message to this incident. New evidence may narrow, expand, or change the known scope.
Sources and evidence boundaries
The complete primary PDF was read and compared with the original SEC filing and company-hosted copy. Company service information, live recruitment, FTC guidance, and Rule 23 supply context. The SEC disclosure controls incident details; broader specific-identifier lists on recruiting pages are not treated as confirmed company facts. Recruitment was checked for this October 10, 2026 article.
An affected total, intrusion date, detection date, person-specific inventory, named plaintiff, court ruling, and recovery terms remain unverified in this source set. No inference of stolen patient records follows from the company's notification plans.
Class Action Pulse is not a law firm or settlement administrator. This article provides general information, not legal advice, and does not guarantee eligibility, representation, compensation, or any outcome. Consult the linked official materials and qualified counsel for your circumstances.
Frequently asked questions
Did the Astrana incident happen on September 22?
The filing says Astrana determined materiality as of September 22, 2026. It does not provide a verified intrusion or detection date. September 23 is the filing date.
Were patient records or Social Security numbers confirmed stolen?
No specific patient data category or Social Security number exposure is confirmed by this filing. Astrana says it believes certain private or confidential information was accessed or acquired and is still evaluating affected information and people.
Who are attorneys asking to contact them?
ClassAction.org invites people who believe information may have been affected, including employees, credentialed providers, and patients. Levi & Korsinsky specifically invites current or former patients of providers using Astrana services. Neither invitation establishes a court-defined class.
Does Astrana's cybersecurity insurance guarantee a payment?
No. The filing discusses insurance that may cover certain company losses, with no assurance of sufficient coverage. It does not establish a patient payment program, settlement, or guaranteed recovery.
Sources
- Astrana Health, September 23, 2026 Form 8-K, Item 1.05, original SEC EDGAR filing
- Astrana Health, same September 23 filing on company investor-relations site
- Astrana Health, official services and patient-care overview
- ClassAction.org, live Astrana investigation and recruitment
- Levi & Korsinsky, direct Astrana investigation and patient recruitment
- Federal Trade Commission, medical identity theft guidance
- Federal Trade Commission, credit freezes and fraud alerts
- Federal Rule of Civil Procedure 23, class certification and settlement safeguards
- Astrana Health, current company SEC filing index checked October 10, 2026
