// AI threat desk · 5 Oct 2026
Home/LEAK · Data Leaks
Data LeaksMediumPHICVSS not assigned

Clover Health and AngMar report breaches affecting 250,000 people

Clover Health Investments and AngMar Management Services reported separate healthcare breaches affecting more than 250,000 people, SecurityWeek reported.

AI-generated image of a healthcare security operations centre with staff, monitors, and a server-room corridor.
AI-generated image, not a photo of the event.
Key takeaways
  • SecurityWeek reported that Clover Health and AngMar had separate breaches affecting more than 250,000 people in total.
  • SecurityWeek reported that Clover Health’s incident involved social engineering and three compromised employee accounts.
  • SecurityWeek reported that AngMar’s affected information included medical, insurance and identity data.

Clover Health Investments and AngMar Management Services notified more than 250,000 people about separate healthcare data breaches, SecurityWeek reported. The incidents affected health and patient information at the two organizations.

Clover Health’s incident followed social engineering that compromised three non-managerial employee accounts. AngMar’s incident involved suspicious activity on its systems, followed by confirmation that hackers had taken patient personal and protected health information.

On this page

Clover Health incident involved compromised employee accounts

The potentially affected Clover Health information included names, dates of birth, insurance identifiers and account identification numbers.

AngMar listed patient and clinical information among affected data

SecurityWeek reported that AngMar identified suspicious activity in mid-July and confirmed in early September that hackers had taken patient personal and protected health information.

The impacted information included names, birth dates, Social Security numbers, diagnosis details, medical history, health insurance information, patient IDs, provider names, prescription details and dates of service.

The Interlock ransomware group added AngMar to its Tor-based leak site in August and claimed to have taken over 700 gigabytes of data, SecurityWeek reported.

SecurityWeek reported that Clover Health told the U.S. Department of Health and Human Services that 138,677 people were affected, while AngMar notified the agency that 126,196 individuals were affected.

SecurityWeek said HHS added both organizations to its data breaches portal last week.

FAQ

What happened to Clover Health and AngMar Management Services?

SecurityWeek reported that the two healthcare organizations had separate data breaches affecting more than 250,000 people in total.

How many people were affected by the Clover Health breach?

Clover Health told HHS that 138,677 people were affected, SecurityWeek reported.

What information was exposed in the AngMar breach?

SecurityWeek reported that the information included names, birth dates, Social Security numbers, diagnosis details, medical history, insurance information, patient IDs, provider names, prescription details and dates of service.

Was AngMar targeted by ransomware?

SecurityWeek reported that the Interlock ransomware group added AngMar to its Tor-based leak site and claimed to have taken over 700 gigabytes of data.

What caused the Clover Health breach?

SecurityWeek reported that attackers used social engineering to compromise three non-managerial employee accounts.

Sources

  1. 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms, SecurityWeek
How we checked this story
ClaimSourceStatus
SecurityWeek reported that Clover Health Investments and AngMar Management Services notified more than 250,000 people about separate data breaches.SecurityWeekAttributed
SecurityWeek reported that attackers hacked Clover Health Investments in early July after using social engineering to compromise three non-managerial employee accounts.SecurityWeekAttributed
SecurityWeek reported that the Clover Health incident resulted in the theft of personally identifiable and protected health information.SecurityWeekAttributed
SecurityWeek reported that Clover Health said the potentially affected information included names, dates of birth, insurance identifiers, and account identification numbers.SecurityWeekAttributed
SecurityWeek reported that Clover Health told the U.S. Department of Health and Human Services in mid-September that 138,677 people were affected.Clover Health Investments, via SecurityWeekAttributed
SecurityWeek reported that HHS added Clover Health Investments to its data breaches portal last week.SecurityWeekAttributed
SecurityWeek reported that AngMar Management Services identified suspicious activity in mid-July and confirmed in early September that hackers stole patient personal and protected health information.SecurityWeekAttributed
SecurityWeek reported that AngMar Management Services’ impacted information included names, birth dates, Social Security numbers, diagnosis details, medical history, insurance information, patient IDs, provider names, prescription details, and service dates.SecurityWeekAttributed
SecurityWeek reported that the Interlock ransomware group added AngMar Management Services to its Tor-based leak site in August and claimed to have stolen over 700 gigabytes of data.SecurityWeekAttributed
SecurityWeek reported that AngMar Management Services notified HHS on September 16 that 126,196 individuals were affected.SecurityWeekAttributed
SecurityWeek reported that HHS added AngMar Management Services to its data breach portal last week.SecurityWeekAttributed
SecurityWeek reported that AngMar Management Services provides business operations, administration, and support network management for home health and hospice care providers.SecurityWeekAttributed

Could not verify

  • Whether the breaches were linked is not established
  • Whether the stolen information was used for fraud is not established
  • Whether the Interlock ransomware group actually stole over 700 gigabytes is not established
Explore with AI