Clover Health Discloses Data Breach Affecting Employee Accounts
On July 4, Tennessee-based insurer Clover Health detected a cybersecurity breach after hackers compromised the accounts of three employees. The attackers gained access to personally identifiable information (PII) and protected health information (PHI) through a social engineering attack, though the company confirmed the employees did not have access to corporate financial or claims systems.
Clover Health, which operates a Medicare Advantage insurance business and the Clover Assistant software platform, took immediate steps to contain the breach, notified law enforcement, and launched an investigation. While the company believes its rapid response successfully terminated the unauthorized access, it has not yet determined the full scope of exposed data or the number of affected individuals. With nearly 156,000 members across five states, the potential impact remains unclear.
The breach highlights the growing threat of social engineering attacks such as phishing in the healthcare sector, where outdated IT systems and limited cybersecurity resources make organizations prime targets for cybercriminals seeking valuable medical and personal data. Clover Health stated it is strengthening its cybersecurity measures but does not expect the incident to materially affect its operations or finances. The company, which reported a $1.3 million loss in Q1 2025, anticipates its first profitable year in 2026 under GAAP standards.
The disclosure comes as healthcare data breaches continue to rise, with recent high-profile incidents underscoring the sector’s vulnerability. Clover Health has not responded to requests for further details.
Source: https://www.healthcaredive.com/news/clover-health-data-breach/825628/
Clover Health cybersecurity rating report: https://www.rankiteo.com/company/cloverhealth
"id": "CLO1784566293",
"linkid": "cloverhealth",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Healthcare',
'location': 'Tennessee, USA',
'name': 'Clover Health',
'type': 'Insurer'}],
'attack_vector': 'Social Engineering',
'data_breach': {'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally identifiable '
'information (PII)',
'Protected health information '
'(PHI)']},
'date_detected': '2025-07-04',
'description': 'On July 4, Tennessee-based insurer Clover Health detected a '
'cybersecurity breach after hackers compromised the accounts '
'of three employees. The attackers gained access to personally '
'identifiable information (PII) and protected health '
'information (PHI) through a social engineering attack. The '
'company confirmed the employees did not have access to '
'corporate financial or claims systems. Clover Health took '
'immediate steps to contain the breach, notified law '
'enforcement, and launched an investigation. The company '
'believes its rapid response successfully terminated the '
'unauthorized access but has not yet determined the full scope '
'of exposed data or the number of affected individuals.',
'impact': {'data_compromised': 'Personally identifiable information (PII) and '
'protected health information (PHI)',
'operational_impact': 'Not expected to materially affect '
'operations or finances',
'systems_affected': 'Employee accounts'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Growing threat of social engineering attacks in the '
'healthcare sector, where outdated IT systems and limited '
'cybersecurity resources make organizations prime targets.',
'recommendations': 'Strengthening cybersecurity measures',
'response': {'containment_measures': 'Immediate steps to contain the breach',
'incident_response_plan_activated': 'Yes',
'law_enforcement_notified': 'Yes'},
'title': 'Clover Health Discloses Data Breach Affecting Employee Accounts',
'type': 'Data Breach'}