← BACK TO FEED
data breachhealthcaresocial engineeringSEC disclosureHIPAA

Clover Health Investments Hit by Social Engineering Attack, Patient Data Exposed

Clover Health Investments disclosed a data breach discovered on July 4, resulting from a social engineering attack that compromised three non-managerial employee accounts with access to personal and protected health information. The company activated its response plan, engaged third-party cybersecurity experts, and believes the attackers have been evicted, though the full scope of the breach remains undetermined. No threat actor or ransomware group has claimed responsibility for the incident.

Clover Health Investments has notified regulators of a data breach affecting customers' personal and protected health information, after attackers used social engineering to compromise staff accounts on 4 July.

Three non-managerial health plan employees had their accounts taken over. Both had scheduling and broker-facing sales responsibilities, meaning the accounts held access to personally identifiable information and protected health data. No financial systems or claims infrastructure was touched, according to the company's SEC filing.

Clover says it triggered its incident response plan promptly and pulled in third-party cybersecurity specialists to contain the intrusion. It believes the attackers have since been evicted, though the full scope of what was accessed or exfiltrated remains unclear.

No ransomware group has stepped forward to claim the attack, and Clover has said nothing publicly about who was behind it.

Social engineering remains stubbornly effective against healthcare organisations. Staff with access to scheduling or sales functions are rarely seen as high-value targets, which probably makes them attractive ones. Frontline employees handling member data tend to get less security scrutiny than executives, and attackers know it.

Founded in 2014, Clover operates Medicare Advantage insurance plans and holds direct US government contracts, which adds some regulatory weight to the incident beyond the standard HIPAA obligations.

The company has yet to confirm how many individuals are affected.

READ NEXT
AdaptHealth Blames Social Engineering After Patient Data Walks Out the DoorEstée Lauder Confirms Employee Data Stolen in Oracle EBS Zero-Day AttackSuno Data Breach Exposes 55 Million Users, Plus Some Awkward Scraping Receipts