Clover Health discloses July 4 breach of patient data
A July 4 social-engineering attack compromised three non-managerial Clover Health employee accounts, exposing customers’ personal and protected health information, the company disclosed in an SEC filing.
Clover Health Investments disclosed in a U.S. Securities and Exchange Commission filing that a social-engineering attack discovered on July 4 compromised three non-managerial employee accounts and exposed customers’ personal and protected health information.
The filing identifies the accounts as assigned to employees who handled member visit scheduling and broker-facing sales functions. It notes the accounts had access to certain personally identifiable information and protected health information.
Clover Health activated its incident response plan immediately after discovery and engaged outside cybersecurity specialists to contain and investigate the intrusion. The company reports it believes it contained the activity and removed the intruders from its systems.
Investigators have not yet determined the precise nature, scope or extent of the data exposure. The company has not provided a count of affected members or specified the types of protected health information that may have been accessed.
The filing states the compromised accounts lacked access to corporate financial systems and claims processing. The accounts were non-managerial and tied to health plan operations rather than core back-end systems.
No threat actor is identified in the filing, and no known ransomware or extortion group has publicly claimed responsibility. The filing does not state whether law enforcement was notified.
Founded in 2014, Clover Health offers Medicare Advantage plans and operates as a direct contractor with the U.S. government. The company plans to continue the investigation and to provide updates as more information becomes available.








