Clover Health Investments Hit by Social Engineering Attack, Patient Data Exposed
Clover Health Investments has notified regulators of a data breach affecting customers' personal and protected health information, after attackers used social engineering to compromise staff accounts on 4 July.
Three non-managerial health plan employees had their accounts taken over. Both had scheduling and broker-facing sales responsibilities, meaning the accounts held access to personally identifiable information and protected health data. No financial systems or claims infrastructure was touched, according to the company's SEC filing.
Clover says it triggered its incident response plan promptly and pulled in third-party cybersecurity specialists to contain the intrusion. It believes the attackers have since been evicted, though the full scope of what was accessed or exfiltrated remains unclear.
No ransomware group has stepped forward to claim the attack, and Clover has said nothing publicly about who was behind it.
Social engineering remains stubbornly effective against healthcare organisations. Staff with access to scheduling or sales functions are rarely seen as high-value targets, which probably makes them attractive ones. Frontline employees handling member data tend to get less security scrutiny than executives, and attackers know it.
Founded in 2014, Clover operates Medicare Advantage insurance plans and holds direct US government contracts, which adds some regulatory weight to the incident beyond the standard HIPAA obligations.
The company has yet to confirm how many individuals are affected.