Clover Health discloses data breach affecting customer data
This digest was compiled by AI from multiple sources — links to the originals are below.

Healthcare technology company Clover Health Investments disclosed a data breach impacting customers' personal and health information. The incident, discovered on July 4, resulted from a social engineering attack that compromised three employee accounts. The company has contained the breach but has not determined its full scope.
The Breach
Clover Health Investments disclosed a data breach in a filing with the US Securities and Exchange Commission (SEC). The incident, discovered on July 4, involved a social engineering attack that compromised three non-managerial health plan employee accounts. The compromised accounts had access to personally identifiable information and protected health information but not to corporate financial or claims systems.
Company Response
Clover Health activated its response plan immediately and engaged third-party cybersecurity experts to contain and investigate the intrusion. The company believes it has evicted the attackers from its systems but has yet to determine the precise nature, scope, and extent of the data breach. No known ransomware or extortion group has claimed responsibility.
Company Background
Founded in 2014, Clover Health Investments provides Medicare Advantage insurance plans and is a direct US government contractor. The company has not shared details on the threat actor behind the attack. SecurityWeek has emailed Clover Health for additional information.
What's Next
Clover Health is expected to provide further updates as its investigation progresses. It remains unclear how many customers were affected or whether the stolen data will be misused.
1 source
Clover Health discloses data breach affecting customer data



