2026 Clover Health — social-engineering breach of 3 employee accounts; member PHI accessed
Data compromised
Per SEC Form 8-K: affected accounts used for member visit-scheduling and broker-facing sales and had access to certain PII and PHI; no access to corporate financial or claims systems; member notification scope pending investigation
Technical writeup
Verified SEC disclosure — event date July 4, 2026; Form 8-K filed July 17, 2026. Clover Health Investments, Corp. detected anomalous login activity, activated incident response, and found a threat actor accessed three non-managerial health-plan employee accounts through social engineering. The accounts supported member visit-scheduling and broker-facing sales and could reach certain personally identifiable and protected health information, but had no access to corporate financial or claims systems. Clover said its response contained the unauthorized access and, based on information available at filing, did not expect a material business impact, though the investigation into the precise nature, scope, and extent of any data acquisition remained ongoing. The company notified law enforcement and said it would make required member notifications as findings mature.
Root cause
Threat actor gained access to three non-managerial health-plan employee accounts via social engineering on July 4, 2026
References
- https://www.sec.gov/Archives/edgar/data/1801170/000180117026000181/clov-20260704.htm
- https://finance.yahoo.com/healthcare/articles/clover-health-says-employee-accounts-204909070.html
- https://www.beckerspayer.com/virtual-care/clover-health-reports-data-breach/
- https://www.securityweek.com/clover-health-investments-discloses-data-breach/
- https://www.fiercehealthcare.com/health-tech/clover-health-reveals-data-breach-sec-filing
- https://classactionu.org/current-data-breaches/clover-health/