- SecurityWeek reported that Clover Health and AngMar had separate breaches affecting more than 250,000 people in total.
- SecurityWeek reported that Clover Health’s incident involved social engineering and three compromised employee accounts.
- SecurityWeek reported that AngMar’s affected information included medical, insurance and identity data.
Clover Health Investments and AngMar Management Services notified more than 250,000 people about separate healthcare data breaches, SecurityWeek reported. The incidents affected health and patient information at the two organizations.
Clover Health’s incident followed social engineering that compromised three non-managerial employee accounts. AngMar’s incident involved suspicious activity on its systems, followed by confirmation that hackers had taken patient personal and protected health information.
On this page
Clover Health incident involved compromised employee accounts
The potentially affected Clover Health information included names, dates of birth, insurance identifiers and account identification numbers.
AngMar listed patient and clinical information among affected data
SecurityWeek reported that AngMar identified suspicious activity in mid-July and confirmed in early September that hackers had taken patient personal and protected health information.
The impacted information included names, birth dates, Social Security numbers, diagnosis details, medical history, health insurance information, patient IDs, provider names, prescription details and dates of service.
The Interlock ransomware group added AngMar to its Tor-based leak site in August and claimed to have taken over 700 gigabytes of data, SecurityWeek reported.
SecurityWeek reported that Clover Health told the U.S. Department of Health and Human Services that 138,677 people were affected, while AngMar notified the agency that 126,196 individuals were affected.
SecurityWeek said HHS added both organizations to its data breaches portal last week.
FAQ
What happened to Clover Health and AngMar Management Services?
SecurityWeek reported that the two healthcare organizations had separate data breaches affecting more than 250,000 people in total.
How many people were affected by the Clover Health breach?
Clover Health told HHS that 138,677 people were affected, SecurityWeek reported.
What information was exposed in the AngMar breach?
SecurityWeek reported that the information included names, birth dates, Social Security numbers, diagnosis details, medical history, insurance information, patient IDs, provider names, prescription details and dates of service.
Was AngMar targeted by ransomware?
SecurityWeek reported that the Interlock ransomware group added AngMar to its Tor-based leak site and claimed to have taken over 700 gigabytes of data.
What caused the Clover Health breach?
SecurityWeek reported that attackers used social engineering to compromise three non-managerial employee accounts.
Sources
How we checked this story
| Claim | Source | Status |
|---|---|---|
| SecurityWeek reported that Clover Health Investments and AngMar Management Services notified more than 250,000 people about separate data breaches. | SecurityWeek | Attributed |
| SecurityWeek reported that attackers hacked Clover Health Investments in early July after using social engineering to compromise three non-managerial employee accounts. | SecurityWeek | Attributed |
| SecurityWeek reported that the Clover Health incident resulted in the theft of personally identifiable and protected health information. | SecurityWeek | Attributed |
| SecurityWeek reported that Clover Health said the potentially affected information included names, dates of birth, insurance identifiers, and account identification numbers. | SecurityWeek | Attributed |
| SecurityWeek reported that Clover Health told the U.S. Department of Health and Human Services in mid-September that 138,677 people were affected. | Clover Health Investments, via SecurityWeek | Attributed |
| SecurityWeek reported that HHS added Clover Health Investments to its data breaches portal last week. | SecurityWeek | Attributed |
| SecurityWeek reported that AngMar Management Services identified suspicious activity in mid-July and confirmed in early September that hackers stole patient personal and protected health information. | SecurityWeek | Attributed |
| SecurityWeek reported that AngMar Management Services’ impacted information included names, birth dates, Social Security numbers, diagnosis details, medical history, insurance information, patient IDs, provider names, prescription details, and service dates. | SecurityWeek | Attributed |
| SecurityWeek reported that the Interlock ransomware group added AngMar Management Services to its Tor-based leak site in August and claimed to have stolen over 700 gigabytes of data. | SecurityWeek | Attributed |
| SecurityWeek reported that AngMar Management Services notified HHS on September 16 that 126,196 individuals were affected. | SecurityWeek | Attributed |
| SecurityWeek reported that HHS added AngMar Management Services to its data breach portal last week. | SecurityWeek | Attributed |
| SecurityWeek reported that AngMar Management Services provides business operations, administration, and support network management for home health and hospice care providers. | SecurityWeek | Attributed |
Could not verify
- Whether the breaches were linked is not established
- Whether the stolen information was used for fraud is not established
- Whether the Interlock ransomware group actually stole over 700 gigabytes is not established



