ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Clover Health discloses data breach after hackers accessed employee accounts

Clover Health disclosed in a securities filing submitted July 17 that hackers breached the accounts of three employees, potentially exposing members’ personal and protected health information. The Tennessee-based insurer and physician enablement company said it discovered the intrusion on July 4 and has not yet determined what data was accessed or how many people may be affected.


According to the filing submitted to the Securities and Exchange Commission, Clover detected anomalous login activity on its information systems and activated response procedures, including bringing in outside cybersecurity experts to contain the threat. The company’s investigation determined that a threat actor gained access to three non-managerial health plan employee accounts through social engineering, a tactic in which hackers manipulate individuals into granting system access or disclosing sensitive information.


The affected employees worked in roles supporting broker-facing sales functions and member visit scheduling, giving them access to certain personal data and protected health information. Clover said these employees did not have access to the company’s corporate financial or claims systems.


Clover stated that its investigation into the precise nature and extent of the compromised data remains ongoing, and the company has not disclosed whether any information was stolen. As the inquiry continues, Clover said it will issue regulatory disclosures and conduct outreach to affected members as required. The company also said it is working to strengthen its IT infrastructure.


"The Company believes that its rapid response successfully contained and terminated the unauthorized access," Clover said in the filing.


The insurer said it does not anticipate the breach will materially affect its business operations or financial results. A Clover Health spokesperson told Fierce Healthcare that the investigation remains ongoing and that the company is limited in what it can share at this time.


"Protecting our members’ data remains our highest priority and we are taking this matter seriously," the spokesperson said.


Clover serves nearly 156,000 members across five states. The company was founded in 2014 and went public in early 2021, building a Medicare Advantage insurance business alongside its Clover Assistant software platform, which compiles patient data to support clinicians in treatment decisions. Despite rapid enrollment growth, the company has historically struggled to achieve consistent profitability. In the first quarter of 2026, Clover reported more than $27 million in profit, a reversal from a $1.3 million loss in the same period the previous year, and the company expects 2026 to mark its first profitable year under generally accepted accounting principles.


The disclosure follows a pattern of high-profile healthcare breaches in recent years. In 2024, a ransomware attack on Change Healthcare, a subsidiary of UnitedHealth Group, compromised the data of more than 190 million people, over half the U.S. population. UnitedHealth executives attributed the attack to a lack of basic cybersecurity protocols, and the company spent $3.1 billion recovering from the incident.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543