Clover Health has disclosed a data breach in a new securities filing, though details on the incident are scarce.
The company said in a filing with the Securities and Exchange Commission, submitted July 17, that on July 4 it discovered "anomalous login activity on certain of its information systems." When the intrusion was uncovered, Clover activated response procedures and contacted third-party experts to contain the threat.
"The investigation subsequently showed that a threat actor gained access to three non-managerial health plan employee accounts through social engineering," Clover said in the document.
Those employees, the company said, had access to broker-facing sales functions as well as tools for scheduling member visits. This includes access to potential personal data and protected health information, though not to corporate financial systems or claims.
Clover said in the filing that the "investigation is ongoing into the precise nature, scope, and extent of data that was subject to unauthorized access and acquisition," so details on how many individuals may have been impacted are limited.
The insurer said that as the investigation continues, it will make necessary regulatory disclosures as well as conduct required outreach to members. Clover added that it continues to "harden its IT environment."
"The Company believes that its rapid response successfully contained and terminated the unauthorized access," per the filing.
Clover also said in the filing that it does not believe the breach will materially impact its business operations or finances moving forward.
A Clover Health spokesperson told Fierce Healthcare that the "investigation remains ongoing and we are limited in the information we can share."
"Protecting our members’ data remains our highest priority and we are taking this matter seriously," the spokesperson said.
Given the treasure trove of data available at healthcare organizations coupled with aging technology, health companies are a prime target for hackers and cybersecurity threats. A 2025 analysis found that the industry remained a top option for hackers as attacks continued to rise through 2024, with a particular uptick in ransomware.
Notably in 2024, the massive cyberattack on UnitedHealth Group's Change Healthcare unit captured headlines, with the company revealing that the hack ultimately impacted 190 million people.