Two Healthcare Firms Suffer Data Breaches, Exposing 250,000 Patients' Information
Clover Health Investments and AngMar Management Services have reported separate data breaches impacting approximately 250,000 individuals, with patient data including PII and PHI being exfiltrated.

Two healthcare organizations, Clover Health Investments and AngMar Management Services, are in the process of notifying over 250,000 individuals that their sensitive personal and protected health information was compromised in separate data security incidents that occurred in July.
Jersey City, New Jersey-based Clover Health Investments disclosed that its systems were breached in early July. The attackers gained access by compromising three employee accounts through social engineering tactics. The compromised information included personally identifiable information (PII) and protected health information (PHI), according to a filing with the Securities and Exchange Commission (SEC). The potentially affected data encompasses names, dates of birth, insurance identifiers, and account identification numbers.
Clover Health Investments officially reported the incident to the U.S. Department of Health and Human Services (HHS) on September 15, stating that 138,677 individuals were impacted. The company was subsequently added to the HHS's data breaches portal.
In a separate incident, Mansfield, Texas-based AngMar Management Services, a provider of business operations and support for home health and hospice care providers, detected suspicious activity on its network in mid-July. By early September, the company confirmed that unauthorized actors had accessed and stolen patient PII and PHI.
The scope of compromised data at AngMar Management Services is extensive, including names, birth dates, Social Security numbers, diagnosis details, medical history, health insurance information, patient IDs, provider names, prescription details, and dates of service. The ransomware group Interlock claimed responsibility for this breach in August, asserting they had exfiltrated over 700 gigabytes of data and listed AngMar Management Services on their Tor-based leak site.
AngMar Management Services notified HHS on September 16, reporting that 126,196 individuals were affected by the breach. This incident also led to the company's inclusion on the HHS data breach portal.
While specific details regarding the attack vectors or malware used in either breach were not immediately provided, the incidents highlight ongoing cybersecurity challenges within the healthcare sector. The use of social engineering against Clover Health and the ransomware group's involvement with AngMar Management Services underscore the diverse threats facing healthcare providers.
These breaches serve as a stark reminder of the critical need for robust security measures, employee training, and rapid incident response protocols to protect sensitive patient data from increasingly sophisticated cyber threats.