Form 8-K
8-K — Astrana Health, Inc.
Accession: 0001104659-26-109813
Filed: 2026-09-23
Period: 2026-09-22
CIK: 0001083446
SIC: 8742 (SERVICES-MANAGEMENT CONSULTING SERVICES)
Item: <ITEMS>1.05
Documents
8-K — asth-20260922x8k.htm (Primary)
XML — IDEA: XBRL DOCUMENT (R1.htm)
XML — IDEA: XBRL DOCUMENT (R2.htm)
8-K
8-K (Primary)
Filename: asth-20260922x8k.htm · Sequence: 1
ASTRANA HEALTH, INC._September 22, 2026
0001083446false00010834462026-09-222026-09-22
UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
Washington, DC 20549
FORM 8-K
CURRENT REPORT
Pursuant to Section 13 or 15(d) of the
Securities Exchange Act of 1934
Date of report (Date of earliest event reported): September 22, 2026
ASTRANA HEALTH, INC.
(Exact Name of Registrant as Specified in Charter)
Delaware
001-37392
95-4472349
(State or Other Jurisdiction
(Commission
(I.R.S. Employer
of Incorporation)
File Number)
Identification No.)
1668 S. Garfield Avenue, 2nd Floor, Alhambra, California 91801
(Address of Principal Executive Offices) (Zip Code)
(626) 282-0288
Registrant’s Telephone Number, Including Area Code
(Former Name or Former Address, if Changed Since Last Report)
Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions:
☐ Written communications pursuant to Rule 425 under the Securities Act (17 CFR 230.425)
☐ Soliciting material pursuant to Rule 14a-12 under the Exchange Act (17 CFR 240.14a-12)
☐ Pre-commencement communications pursuant to Rule 14d-2(b) under the Exchange Act (17 CFR 240.14d-2(b))
☐ Pre-commencement communications pursuant to Rule 13e-4(c) under the Exchange Act (17 CFR 240.13e-4(c))
Securities registered pursuant to Section 12(b) of the Act:
Title of each class
Trading symbol(s)
Name of each exchange on which registered
Common Stock, $0.001 par value per share
ASTH
The Nasdaq Stock Market LLC
Indicate by check mark whether the registrant is an emerging growth company as defined in Rule 405 of the Securities Act of 1933 (§230.405 of this chapter) or Rule 12b-2 of the Securities Exchange Act of 1934 (§240.12b-2 of this chapter).
Emerging growth company ☐
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
Item 1.05Material Cybersecurity Incident.
Astrana Health, Inc. (the “Company”) recently became aware that its subsidiary Astrana Health Management, Inc. detected unusual activity within its environment.
The incident involved a series of social engineering attempts in which threat actors, impersonating Company personnel and spoofing the Company’s main corporate telephone number, contacted certain employees in an effort to obtain unauthorized access to Company systems. The Company’s cybersecurity team detected and responded to the unauthorized activity, launched an investigation, engaged a leading third-party cybersecurity and digital forensics firm, notified law enforcement, and is notifying state and federal regulators, and payer partners. The Company has also taken remedial measures, including resetting affected credentials, restricting remote access tools, restoring certain systems from clean backups, and enhancing monitoring, logging, and detection capabilities across its environment. The Company’s investigation into the nature and scope of the incident, including the matters described above, remains ongoing.
Based on the current status of the Company’s ongoing investigation, the Company believes that certain private and/or confidential information maintained on the Company’s servers has been accessed and/or acquired without authorization.
The Company continues to assess whether, and to what extent, patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated and continues to evaluate the potential impact of the unauthorized activity. The Company continues to evaluate applicable regulatory and legal notification requirements, and the Company intends to make all required notifications based on its findings, including to impacted patients.
While the investigation is ongoing, the Company has determined that the incident is material as of September 22, 2026, due to the potential confidential and sensitive nature of the data that is involved.
However, the Company is, at this time, unable to estimate the full potential impact of the incident on the Company’s business strategy, operations, financial condition, or results of operations, including remediation and response costs, legal, regulatory and notification-related matters, and possible effects on providers, patients, counterparties and the Company’s reputation, or the impact on the trading price of the Company’s common stock. The Company maintains cybersecurity insurance that may cover certain losses associated with the incident, although there can be no assurance that such coverage will be sufficient to cover all losses the Company may incur. Although the Company is unable to predict the full impact of this incident, the Company currently does not expect that it will have a material effect on the Company’s financial condition and results of operations.
The trust of our valued providers, patients, and payer partners is deeply important to us, and we regret any concern or inconvenience this may cause.
To the extent any information required by Item 1.05(a) of Form 8-K was not determined or was unavailable at the time of this filing, the Company will amend this Current Report on Form 8-K as such information is determined or becomes available.
Forward-Looking Statements
This Current Report on Form 8-K contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended. These statements include words such as “forecast,” “guidance,” “projects,” “estimates,” “anticipates,” “believes,” “expects,” “intends,” “may,” “plans,” “seeks,” “should,” or “will,” or the negative of these words or similar words. Forward-looking statements involve certain risks and uncertainties, and actual results may differ materially from those discussed in each such statement. These forward-looking statements reflect current beliefs, understanding, and expectations regarding the incident, its impact on the Company, and its remediation and investigation. A number of important factors could cause actual results to differ materially from those included within or contemplated by the forward-looking statements, including, but not limited to, the ongoing assessment of the cybersecurity incident and analysis of the scope and details of the incident and the potential discovery of new and additional information related thereto; the Company’s expectations regarding its ability to contain and remediate the cybersecurity incident, including the success of containment and remediation activities to date; any unauthorized release of the Company’s data, including third-party data held by the Company, or the use of any such data for fraudulent purposes; potential loss or destruction of Company data or adverse impacts to the Company’s operations; the impact of the cybersecurity incident on the Company’s relationships with customers, employees, governmental regulators, and other stakeholders; diversion of management’s attention from the Company’s operations to address the cybersecurity incident; legal, regulatory, reputational, and financial risks resulting from the incident or any additional cybersecurity incidents, including those that may arise from any potential regulatory inquiries and/or litigation to which the Company may become subject in connection with the incident; other reputational risk related to the cybersecurity incident; regulatory scrutiny of the cybersecurity incident; risks related to the availability and adequacy of the Company’s insurance coverage for losses and costs associated with the cybersecurity incident; remediation and other additional costs that may be incurred by the Company in connection with the investigation and remediation of the cybersecurity incident; and the factors described in the Company’s filings with the Securities and Exchange Commission, including the Company’s last Annual Report on Form 10-K and subsequent quarterly reports on Form 10-Q. The Company does not undertake any responsibility to update any of these factors or to announce publicly any revisions to any of the forward-looking statements contained in this or any other document, whether as a result of new information, future events, or otherwise, except as may be required by any applicable securities laws.
SIGNATURES
Pursuant to the requirements of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned hereunto duly authorized.
ASTRANA HEALTH, INC.
Date: September 23, 2026
By:
/s/ Brandon K. Sim
Name:
Brandon K. Sim
Title:
Chief Executive Officer and President
XML — IDEA: XBRL DOCUMENT
XML
Filename: R1.htm · Sequence: 6
v3.26.3
Document and Entity Information
Sep. 22, 2026
Document and Entity Information
Document Type
8-K
Document Period End Date
Sep. 22, 2026
Entity Registrant Name
ASTRANA HEALTH, INC.
Entity Incorporation, State or Country Code
DE
Entity File Number
001-37392
Entity Tax Identification Number
95-4472349
Entity Address, Address Line One
1668 S. Garfield Avenue
Entity Address, Adress Line Two
2nd Floor
Entity Address, City or Town
Alhambra
Entity Address State Or Province
CA
Entity Address, Postal Zip Code
91801
City Area Code
626
Local Phone Number
282-0288
Written Communications
false
Soliciting Material
false
Pre-commencement Tender Offer
false
Pre-commencement Issuer Tender Offer
false
Title of 12(b) Security
Common Stock, $0.001 par value per share
Trading Symbol
ASTH
Security Exchange Name
NASDAQ
Entity Emerging Growth Company
false
Entity Central Index Key
0001083446
Amendment Flag
false
X
- Definition
Boolean flag that is true when the XBRL content amends previously-filed or accepted submission.
+ References
No definition available.
+ Details
Name:
dei_AmendmentFlag
Namespace Prefix:
dei_
Data Type:
xbrli:booleanItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Area code of city
+ References
No definition available.
+ Details
Name:
dei_CityAreaCode
Namespace Prefix:
dei_
Data Type:
xbrli:normalizedStringItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Cover page.
+ References
No definition available.
+ Details
Name:
dei_CoverAbstract
Namespace Prefix:
dei_
Data Type:
xbrli:stringItemType
Balance Type:
na
Period Type:
duration
X
- Definition
For the EDGAR submission types of Form 8-K: the date of the report, the date of the earliest event reported; for the EDGAR submission types of Form N-1A: the filing date; for all other submission types: the end of the reporting or transition period. The format of the date is YYYY-MM-DD.
+ References
No definition available.
+ Details
Name:
dei_DocumentPeriodEndDate
Namespace Prefix:
dei_
Data Type:
xbrli:dateItemType
Balance Type:
na
Period Type:
duration
X
- Definition
The type of document being provided (such as 10-K, 10-Q, 485BPOS, etc). The document type is limited to the same value as the supporting SEC submission type, or the word 'Other'.
+ References
No definition available.
+ Details
Name:
dei_DocumentType
Namespace Prefix:
dei_
Data Type:
dei:submissionTypeItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Address Line 1 such as Attn, Building Name, Street Name
+ References
No definition available.
+ Details
Name:
dei_EntityAddressAddressLine1
Namespace Prefix:
dei_
Data Type:
xbrli:normalizedStringItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Address Line 2 such as Street or Suite number
+ References
No definition available.
+ Details
Name:
dei_EntityAddressAddressLine2
Namespace Prefix:
dei_
Data Type:
xbrli:normalizedStringItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Name of the City or Town
+ References
No definition available.
+ Details
Name:
dei_EntityAddressCityOrTown
Namespace Prefix:
dei_
Data Type:
xbrli:normalizedStringItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Code for the postal or zip code
+ References
No definition available.
+ Details
Name:
dei_EntityAddressPostalZipCode
Namespace Prefix:
dei_
Data Type:
xbrli:normalizedStringItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Name of the state or province.
+ References
No definition available.
+ Details
Name:
dei_EntityAddressStateOrProvince
Namespace Prefix:
dei_
Data Type:
dei:stateOrProvinceItemType
Balance Type:
na
Period Type:
duration
X
- Definition
A unique 10-digit SEC-issued value to identify entities that have filed disclosures with the SEC. It is commonly abbreviated as CIK.
+ References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Exchange Act
-Number 240
-Section 12
-Subsection b-2
+ Details
Name:
dei_EntityCentralIndexKey
Namespace Prefix:
dei_
Data Type:
dei:centralIndexKeyItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Indicate if registrant meets the emerging growth company criteria.
+ References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Exchange Act
-Number 240
-Section 12
-Subsection b-2
+ Details
Name:
dei_EntityEmergingGrowthCompany
Namespace Prefix:
dei_
Data Type:
xbrli:booleanItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Commission file number. The field allows up to 17 characters. The prefix may contain 1-3 digits, the sequence number may contain 1-8 digits, the optional suffix may contain 1-4 characters, and the fields are separated with a hyphen.
+ References
No definition available.
+ Details
Name:
dei_EntityFileNumber
Namespace Prefix:
dei_
Data Type:
dei:fileNumberItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Two-character EDGAR code representing the state or country of incorporation.
+ References
No definition available.
+ Details
Name:
dei_EntityIncorporationStateCountryCode
Namespace Prefix:
dei_
Data Type:
dei:edgarStateCountryItemType
Balance Type:
na
Period Type:
duration
X
- Definition
The exact name of the entity filing the report as specified in its charter, which is required by forms filed with the SEC.
+ References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Exchange Act
-Number 240
-Section 12
-Subsection b-2
+ Details
Name:
dei_EntityRegistrantName
Namespace Prefix:
dei_
Data Type:
xbrli:normalizedStringItemType
Balance Type:
na
Period Type:
duration
X
- Definition
The Tax Identification Number (TIN), also known as an Employer Identification Number (EIN), is a unique 9-digit value assigned by the IRS.
+ References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Exchange Act
-Number 240
-Section 12
-Subsection b-2
+ Details
Name:
dei_EntityTaxIdentificationNumber
Namespace Prefix:
dei_
Data Type:
dei:employerIdItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Local phone number for entity.
+ References
No definition available.
+ Details
Name:
dei_LocalPhoneNumber
Namespace Prefix:
dei_
Data Type:
xbrli:normalizedStringItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Boolean flag that is true when the Form 8-K filing is intended to satisfy the filing obligation of the registrant as pre-commencement communications pursuant to Rule 13e-4(c) under the Exchange Act.
+ References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Exchange Act
-Number 240
-Section 13e
-Subsection 4c
+ Details
Name:
dei_PreCommencementIssuerTenderOffer
Namespace Prefix:
dei_
Data Type:
xbrli:booleanItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Boolean flag that is true when the Form 8-K filing is intended to satisfy the filing obligation of the registrant as pre-commencement communications pursuant to Rule 14d-2(b) under the Exchange Act.
+ References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Exchange Act
-Number 240
-Section 14d
-Subsection 2b
+ Details
Name:
dei_PreCommencementTenderOffer
Namespace Prefix:
dei_
Data Type:
xbrli:booleanItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Title of a 12(b) registered security.
+ References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Exchange Act
-Number 240
-Section 12
-Subsection b
+ Details
Name:
dei_Security12bTitle
Namespace Prefix:
dei_
Data Type:
dei:securityTitleItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Name of the Exchange on which a security is registered.
+ References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Exchange Act
-Number 240
-Section 12
-Subsection d1-1
+ Details
Name:
dei_SecurityExchangeName
Namespace Prefix:
dei_
Data Type:
dei:edgarExchangeCodeItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Boolean flag that is true when the Form 8-K filing is intended to satisfy the filing obligation of the registrant as soliciting material pursuant to Rule 14a-12 under the Exchange Act.
+ References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Exchange Act
-Number 240
-Section 14a
-Subsection 12
+ Details
Name:
dei_SolicitingMaterial
Namespace Prefix:
dei_
Data Type:
xbrli:booleanItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Trading symbol of an instrument as listed on an exchange.
+ References
No definition available.
+ Details
Name:
dei_TradingSymbol
Namespace Prefix:
dei_
Data Type:
dei:tradingSymbolItemType
Balance Type:
na
Period Type:
duration
X
- Definition
Boolean flag that is true when the Form 8-K filing is intended to satisfy the filing obligation of the registrant as written communications pursuant to Rule 425 under the Securities Act.
+ References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Securities Act
-Number 230
-Section 425
+ Details
Name:
dei_WrittenCommunications
Namespace Prefix:
dei_
Data Type:
xbrli:booleanItemType
Balance Type:
na
Period Type:
duration
XML — IDEA: XBRL DOCUMENT
XML
Filename: R2.htm · Sequence: 7
v3.26.3
Material Cybersecurity Incident Disclosure
Sep. 22, 2026
Material Cybersecurity Incident [Line Items]
Material Cybersecurity Incident Nature [Text Block]
Astrana Health, Inc. (the “Company”) recently became aware that its subsidiary Astrana Health Management, Inc. detected unusual activity within its environment.
Material Cybersecurity Incident Scope [Text Block]
Astrana Health, Inc. (the “Company”) recently became aware that its subsidiary Astrana Health Management, Inc. detected unusual activity within its environment.
The incident involved a series of social engineering attempts in which threat actors, impersonating Company personnel and spoofing the Company’s main corporate telephone number, contacted certain employees in an effort to obtain unauthorized access to Company systems. The Company’s cybersecurity team detected and responded to the unauthorized activity, launched an investigation, engaged a leading third-party cybersecurity and digital forensics firm, notified law enforcement, and is notifying state and federal regulators, and payer partners. The Company has also taken remedial measures, including resetting affected credentials, restricting remote access tools, restoring certain systems from clean backups, and enhancing monitoring, logging, and detection capabilities across its environment. The Company’s investigation into the nature and scope of the incident, including the matters described above, remains ongoing.
Based on the current status of the Company’s ongoing investigation, the Company believes that certain private and/or confidential information maintained on the Company’s servers has been accessed and/or acquired without authorization.
The Company continues to assess whether, and to what extent, patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated and continues to evaluate the potential impact of the unauthorized activity. The Company continues to evaluate applicable regulatory and legal notification requirements, and the Company intends to make all required notifications based on its findings, including to impacted patients.
Material Cybersecurity Incident Timing [Text Block]
September 22, 2026
Material Cybersecurity Incident Information Not Available or Undetermined [Text Block]
However, the Company is, at this time, unable to estimate the full potential impact of the incident on the Company’s business strategy, operations, financial condition, or results of operations, including remediation and response costs, legal, regulatory and notification-related matters, and possible effects on providers, patients, counterparties and the Company’s reputation, or the impact on the trading price of the Company’s common stock. The Company maintains cybersecurity insurance that may cover certain losses associated with the incident, although there can be no assurance that such coverage will be sufficient to cover all losses the Company may incur. Although the Company is unable to predict the full impact of this incident, the Company currently does not expect that it will have a material effect on the Company’s financial condition and results of operations.
X
- References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Form 8-K
-Section 1.05
-Subsection Instruction
-Paragraph 2
Reference 2: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Form 6-K
-Section General Instruction
-Subsection B
+ Details
Name:
cyd_MaterialCybersecurityIncidentInformationNotAvailableOrUndeterminedTextBlock
Namespace Prefix:
cyd_
Data Type:
dtr-types:textBlockItemType
Balance Type:
na
Period Type:
duration
X
- References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Form 8-K
-Section 1.05
-Subsection a
Reference 2: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Form 6-K
-Section General Instruction
-Subsection B
+ Details
Name:
cyd_MaterialCybersecurityIncidentLineItems
Namespace Prefix:
cyd_
Data Type:
i:stringItemType
Balance Type:
na
Period Type:
duration
X
- References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Form 8-K
-Section 1.05
-Subsection a
Reference 2: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Form 6-K
-Section General Instruction
-Subsection B
+ Details
Name:
cyd_MaterialCybersecurityIncidentNatureTextBlock
Namespace Prefix:
cyd_
Data Type:
dtr-types:textBlockItemType
Balance Type:
na
Period Type:
duration
X
- References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Form 8-K
-Section 1.05
-Subsection a
Reference 2: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Form 6-K
-Section General Instruction
-Subsection B
+ Details
Name:
cyd_MaterialCybersecurityIncidentScopeTextBlock
Namespace Prefix:
cyd_
Data Type:
dtr-types:textBlockItemType
Balance Type:
na
Period Type:
duration
X
- References
Reference 1: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Form 8-K
-Section 1.05
-Subsection a
Reference 2: http://www.xbrl.org/2003/role/presentationRef
-Publisher SEC
-Name Form 6-K
-Section General Instruction
-Subsection B
+ Details
Name:
cyd_MaterialCybersecurityIncidentTimingTextBlock
Namespace Prefix:
cyd_
Data Type:
dtr-types:textBlockItemType
Balance Type:
na
Period Type:
duration