Healthcare Tech Giant Astrana Breached After Staff Impersonation Scam
Astrana, one of the largest healthcare technology companies in the United States, has filed a report with the Securities and Exchange Commission disclosing a cyberattack that exposed confidential information. According to the filing, attackers impersonated Astrana personnel and spoofed the company's main corporate phone number to contact employees, eventually gaining unauthorised access to company servers.
The company says its investigation is ongoing but confirmed that private and confidential information stored on its servers was likely accessed or acquired without authorisation. As part of its response, Astrana restored certain systems from clean backups and notified law enforcement, regulators, and customers. It has not confirmed whether ransomware was involved, and the number of affected customers or the type of data taken has not been disclosed.
Astrana warned that the incident could affect its business strategy, operations, financial position, and reputation, and that cyber insurance may not fully cover the resulting losses. The company processes services for around 20,000 medical providers and reported $972.5 million in revenue last quarter. This breach follows a string of recent attacks on healthcare technology firms, including Veradigm, Nutex, AnMed, Aesto, Baylor Genetics, CareCloud, Paylogix, and Boston Scientific, though no hacking group has yet claimed responsibility for the Astrana incident.