Dive Brief:
- Clover Health has been hit by a data breach, the insurer and physician enablement company disclosed in a securities filing on Friday.
- On July 4, Clover discovered that a hacker had broken into the accounts of three employees and could have accessed members’ personal and protected health information. Clover took steps to contain the breach, notified law enforcement and is still investigating what data could be impacted, according to the filing.
- Clover did not disclose whether any data was stolen or how many people may be affected. The company, which did not respond to a request for information, has almost 156,000 members in five states.
Dive Insight:
Breaches in healthcare have soared over the past decade, as outdated IT systems and limited cybersecurity resources are exploited by bad actors hungry for the lucrative personal and medical data maintained in the sector.
According to Clover’s filing, three employees fell victim to social engineering — when hackers manipulate people into giving them IT access or disclosing information. Phishing, the most common source of data breaches, is one type of social engineering.
The employees worked on scheduling visits for members and Clover’s broker relationships, and had access to certain personally identifiable information and protected health information, according to the disclosure. They did not have access to corporate financial or claims systems.
“While the investigation is ongoing into the precise nature, scope, and extent of data that was subject to unauthorized access and acquisition, the Company believes that its rapid response successfully contained and terminated the unauthorized access,” Clover’s filing reads.
Clover said it’s taking steps to shore up its cybersecurity, though the company doesn’t expect the breach to materially impact its operations or finances. It’s a bright spot for Clover given how drastically data breaches can throw organizations into disarray and how completely recovery expenses can eat into bottom lines.
For example, healthcare behemoth UnitedHealth spent $3.1 billion to recover from a 2024 ransomware attack on its subsidiary Change Healthcare. The attack, which compromised the data of more than 190 million people — more than half the U.S. population — stemmed from a lack of basic cybersecurity protocols, according to UnitedHealth’s executives.
Tennessee-based Clover was founded in 2014 as one of a crop of startups seeking to disrupt the insurance industry. The company maintains a Medicare Advantage insurance business and a software platform Clover Assistant, which aggregates patient data to help clinicians with treatment decisions.
Clover, which went public in early 2021, is one of the fastest-growing MA plans, but it’s struggled to translate growth into sustainable profits.
Still, Clover logged more than $27 million in profit in the first quarter of 2026, up from a $1.3 million loss during the same time last year. The company expects 2026 to be its first profitable year under generally accepted accounting principles.