Clover Health Reports Data Breach After Cyber Intrusion
Advertisement
The Medicare-focused health insurer said it identified “anomalous login activity” on July 4 and immediately activated its incident response procedures while engaging third-party cybersecurity experts to investigate and contain the threat.
Clover Health has revealed a data breach involving unauthorized access to certain employee accounts after detecting suspicious login activity on its information systems, according to a filing submitted with the U.S. Securities and Exchange Commission (SEC) on July 17.
The Medicare-focused health insurer said it identified “anomalous login activity” on July 4 and immediately activated its incident response procedures while engaging third-party cybersecurity experts to investigate and contain the threat.
The investigation found that a threat actor gained access to three non-managerial health plan employee accounts through social engineering tactics, Clover Health stated in the SEC filing.
The compromised accounts were linked to broker-facing sales functions and tools used for scheduling member visits. These systems potentially provided access to personal information and protected health information (PHI). However, Clover said the affected accounts did not provide access to corporate financial systems or claims-related data.
The company said the investigation remains ongoing to determine the “precise nature, scope, and extent” of the information that may have been accessed or acquired. Details regarding the number of individuals potentially impacted have not yet been disclosed.
Clover Health said it will make required regulatory notifications and conduct member outreach if necessary as the investigation progresses. The company also noted that it is continuing efforts to strengthen its information technology environment.
“The Company believes that its rapid response successfully contained and terminated the unauthorized access,” Clover said in the filing.
The insurer added that it does not currently expect the incident to have a material impact on its business operations or financial condition.
A Clover Health spokesperson told Fierce Healthcare that the investigation is ongoing and that the company is limited in the information it can share at this stage. The spokesperson said protecting member data remains a priority and that the company is taking the incident seriously.
Healthcare organizations continue to face rising cybersecurity risks due to the large volume of sensitive patient information they manage. The sector has remained a major target for cybercriminals, with ransomware and other cyber threats increasing in recent years.
The healthcare industry has faced several high-profile breaches, including the 2024 cyberattack on UnitedHealth Group’s Change Healthcare unit, which ultimately affected millions of individuals and disrupted healthcare payment and claims operations.
Stay tuned for more such updates on Digital Health News