Two significant data breaches have impacted over 250,000 individuals, involving healthcare companies Clover Health Investments and AngMar Management Services. Both organizations are currently notifying those affected by these security incidents.
Details of the Clover Health Breach
Clover Health Investments, located in Jersey City, New Jersey, experienced a data breach in early July. Attackers employed social engineering techniques to gain access to three non-managerial employee accounts, compromising sensitive personal and health-related information.
According to a filing with the Securities and Exchange Commission (SEC) in July, the breach exposed personally identifiable information (PII) and protected health information (PHI). The compromised data includes names, birth dates, insurance identifiers, and account numbers.
The company informed the US Department of Health and Human Services (HHS) in mid-September that 138,677 individuals were affected. Recently, HHS included Clover Health in its data breach portal.
AngMar Management Services Data Compromise
In Mansfield, Texas, AngMar Management Services identified unusual activity in its systems in mid-July. By early September, the company confirmed that unauthorized access led to the theft of patient PII and PHI.
AngMar, which supports home health and hospice care providers, reported that the stolen data consisted of names, birth dates, Social Security numbers, diagnosis records, medical histories, insurance information, patient IDs, provider names, prescription details, and service dates.
The Interlock ransomware group claimed responsibility, adding the company to its Tor-based site in August and alleging the theft of over 700 gigabytes of data. AngMar informed HHS on September 16 that 126,196 individuals were affected and was subsequently added to the HHS breach portal.
Implications and Future Outlook
The recent breaches highlight the growing cybersecurity challenges faced by healthcare organizations. The exposure of sensitive information could lead to identity theft and financial fraud, emphasizing the need for enhanced security measures.
As these companies work to remediate the impacts and prevent future breaches, affected individuals are advised to monitor their accounts and report any suspicious activity. The incidents underscore the importance of robust data protection strategies in safeguarding patient privacy.
These breaches serve as a reminder of the potential consequences of cyberattacks, urging organizations across all sectors to prioritize cybersecurity to protect sensitive data.
