A woman in her sixties sees a doctor in a small California practice. Last week her phone rang. The caller knew her clinic by name, knew she had an outstanding balance, and asked her to confirm her insurance member number and date of birth. She gave both, because the call sounded like her clinic. The Astrana Health data breach is the kind of event that makes a call like that possible, and the attackers used the same trick to get in. They phoned Astrana’s own employees from a number that looked like Astrana’s own switchboard.
Confirmation: confirmed by the company in a Form 8-K filed with the SEC on September 23, 2026.
What happened in the Astrana Health data breach
Astrana Health is a California physician-support and healthcare technology company. It works with roughly 20,000 medical providers, so it sits in the middle of a very large amount of patient paperwork.
The attackers did not break a firewall. Instead they used vishing — voice phishing. They impersonated Astrana personnel and spoofed the company’s main corporate phone number, then called employees and talked their way into server access. Astrana told the SEC that “certain private and/or confidential information maintained on the Company’s servers has been accessed and/or acquired without authorization.” The company judged the incident material as of September 22, 2026.
Astrana says it has since rotated credentials, restricted remote access tools, rebuilt systems from clean backups, and added monitoring. So far, no extortion group has claimed the attack.
What was exposed, and what is still unknown
Here is the honest answer: nobody knows yet, including Astrana. The company says it continues to assess whether it took patient, employee, credentialed provider, confidential business and financial information, or intellectual property. That list is what is in scope, not what Astrana has confirmed gone. So far, Astrana has not published a record count. It has said it intends to notify impacted patients once it knows who they are.
That uncertainty matters, because each category carries a different risk. For example, we saw the same pattern in the McKesson data breach, where the record count landed weeks after the first headlines.
- Contact details and email addresses. These are the raw material for a follow-up scam. Someone who knows your clinic can write a message you will believe.
- Insurance and billing records. These support medical identity theft, where a stranger’s treatment shows up on your bill.
- Dates of birth and government IDs. These are the answers to the questions a call center asks to prove you are you.
- Clinical notes. Unlike a card number, nobody can reissue a diagnosis.
What to do now after the Astrana Health data breach
Most of this has nothing to do with us. Do it anyway.
1. Stop trusting caller ID. This attack worked because a spoofed number looked legitimate. Hang up and call back on the number printed on your insurance card or your clinic’s website. 2. Treat any Astrana-flavored email as suspect for the next few months. Breach notices are a favorite disguise, and attackers send theirs before the real one arrives. 3. Use a password manager and give every account its own password. For example, one leaked password should not open a second account. 4. Turn on the strongest sign-in each account offers — a passkey if it exists, an authenticator app if not, SMS only as a last resort. 5. Read your explanation-of-benefits statements. Treatment you did not receive is the clearest sign of medical identity theft. 6. Wait for the official notice before accepting help. Astrana will contact affected patients directly; a caller offering to “verify” you first is not Astrana.
How OptMsg changes this exposure
Let us be precise. The breach happened at another company, and nothing on our side could have stopped it. What changes is the size of the damage on yours.
Your OptMsg account has no password, so nobody can try a password stolen from another site on your inbox. That matters more than it sounds, because your email is what resets most other accounts. So keep that door shut, and the rest stay shut with it.
Then there is the message that comes next. After a breach like this one, the second wave is email dressed up as the breached brand. With OptMsg, mail from a sender you have not approved goes to Trash, not your Inbox, and it auto-deletes after 30 days. So the fake notice lands somewhere you are not reading in a hurry. If lots of other OptMsg users have approved that sender, a Community Recommendation alert tells you something real is waiting in Trash.
What this does not cover, plainly: a compromised device, a live phishing page you type into, an unlocked phone, or a phone call. A voice call reached the woman in the opening paragraph, not a hacked account, so no inbox rule helps there.
Ready for an inbox that works on your terms? Create your OptMsg account and decide who gets through.
Create Your Account
Your Inbox. Your Rules.
Frequently asked questions
Q: Was my data stolen in the Astrana Health data breach? A: Astrana has not published a list or a number yet. The company told the SEC it is still assessing what was taken, and it says it will notify affected patients directly once it knows.
Q: How many people are affected? A: No figure has been disclosed. Astrana works with about 20,000 medical providers, so the potential reach is wide, but a provider count is not a patient count and should not be reported as one.
Q: What is vishing? A: Voice phishing. Someone calls you, pretends to be a person or company you trust, and talks you into handing over access or information. In this case the attackers spoofed Astrana’s own main phone number.
Q: Should I freeze my credit? A: A freeze is free, reversible, and reasonable after any breach involving identity data. It does not stop medical identity theft, so keep reading your explanation-of-benefits statements too.
Q: Will a different email address protect me? A: Partly, and honestly only partly. A separate address for medical accounts limits what a leak connects to the rest of your life. It cannot undo an exposure that already happened.
Sources
- Astrana Health, Inc., Form 8-K, filed September 23, 2026 — https://www.sec.gov/Archives/edgar/data/0001083446/000110465926109813/asth-20260922x8k.htm
- “Astrana Health Data Breach Impacts Private, Confidential Information,” SecurityWeek, September 24, 2026 — https://www.securityweek.com/astrana-health-data-breach-impacts-private-confidential-information/
- “Astrana latest healthcare tech firm to report data breach to SEC,” The Record, September 24, 2026 — https://therecord.media/astrana-cyberattack-sec-ransomware
- “Astrana is latest U.S. healthcare company to face a cyberattack,” Seeking Alpha, September 24, 2026 — https://seekingalpha.com/news/4646011-astrana-stock-drops-cyberattack
Previous in Breach Breakdown: FBI Data Breach: Hackers Say They Hold Agents' and Job Applicants' Home Addresses
Next in Breach Breakdown: Supabase Data Leak: 16,326 Databases Sat Open on the Web