Clover Health Investments Discloses Data Breach
Clover Health Investments suffered a data breach due to a social engineering attack targeting employee accounts. The attackers gained access to member and broker data, but did not reach sensitive corporate financial systems. The company is currently investigating the full scope of the breach and has not yet identified the threat actor. This incident highlights the ongoing risk of social engineering attacks within the healthcare sector.
Clover Health Investments has disclosed a data breach impacting customers’ personal and health information. The incident was the result of a social engineering attack that compromised three non-managerial health plan employee accounts.
Clover Health Investments says it activated its response plan immediately after discovering the attack, and engaged third-party cybersecurity experts to contain and investigate the intrusion. The compromised accounts “were assigned to employees who had member visit-scheduling and broker-facing sales functions,” the company says in a filing with the US Securities and Exchange Commission (SEC).
“The employee accounts had access to certain personally identifiable information and protected health information, but had no access to corporate financial or claims systems,” it said.
Clover Health Investments believes that it contained the incident and evicted the attackers from its systems, but has yet to determine the precise nature, scope, and extent of the data breach.
The company was founded in 2014 and provides Medicare Advantage insurance plans and is a direct US government contractor.
Related: Ernst & Young Data Breach Affects Personal, Financial Information
Related: Hugging Face Hacked in Autonomous AI Attack