Clover Health Investments, a company specializing in healthcare technology, has announced a data breach that has compromised the personal and health information of its customers.
Details of the Breach
The breach was identified on July 4 and was attributed to a social engineering attack. This attack led to the compromise of three employee accounts associated with non-managerial roles within the health plan department.
Upon detection, Clover Health promptly executed its incident response strategy. The company collaborated with external cybersecurity professionals to address and analyze the breach.
Impacted Accounts and Information
According to Clover Health’s filing with the US Securities and Exchange Commission (SEC), the affected accounts were managed by employees involved in scheduling member visits and managing broker-facing sales operations.
These accounts contained access to some personally identifiable and protected health information. However, they did not have entry to corporate financial data or claims systems, minimizing potential exposure.
Ongoing Investigation and Security Measures
While Clover Health believes that it has successfully contained the breach and removed unauthorized access, a comprehensive understanding of the breach’s full impact is still pending.
The company has not identified the perpetrators of the breach, and no ransomware or extortion group has claimed responsibility as of now.
Clover Health continues to monitor the situation closely and has been contacted by SecurityWeek for further comments. Updates will be provided if new information emerges.
Established in 2014, Clover Health offers Medicare Advantage insurance plans and acts as a direct contractor for the US government, emphasizing the importance of maintaining robust cybersecurity measures.
