This story was originally published on Healthcare Dive. To receive daily news and insights, subscribe to our free daily Healthcare Dive newsletter.
Clover Health has been hit by a data breach, the insurer and physician enablement company disclosed in a securities filing on Friday.
On July 4, Clover discovered that a hacker had broken into the accounts of three employees and could have accessed members' personal and protected health information. Clover took steps to contain the breach, notified law enforcement and is still investigating what data could be impacted, according to the filing.
Clover did not disclose whether any data was stolen or how many people may be affected. The company, which did not respond to a request for information, has almost 156,000 members in five states.
Breaches in healthcare have soared over the past decade, as outdated IT systems and limited cybersecurity resources are exploited by bad actors hungry for the lucrative personal and medical data maintained in the sector.
According to Clover's filing, three employees fell victim to social engineering — when hackers manipulate people into giving them IT access or disclosing information. Phishing, the most common source of data breaches, is one type of social engineering.
The employees worked on scheduling visits for members and Clover's broker relationships, and had access to certain personally identifiable information and protected health information, according to the disclosure. They did not have access to corporate financial or claims systems.
"While the investigation is ongoing into the precise nature, scope, and extent of data that was subject to unauthorized access and acquisition, the Company believes that its rapid response successfully contained and terminated the unauthorized access," Clover's filing reads.
Clover said it's taking steps to shore up its cybersecurity, though the company doesn't expect the breach to materially impact its operations or finances. It's a bright spot for Clover given how drastically data breaches can throw organizations into disarray and how completely recovery expenses can eat into bottom lines.
For example, healthcare behemoth UnitedHealth spent $3.1 billion to recover from a 2024 ransomware attack on its subsidiary Change Healthcare. The attack, which compromised the data of more than 190 million people — more than half the U.S. population — stemmed from a lack of basic cybersecurity protocols, according to UnitedHealth's executives.
Source: Yahoo Finance Top News — This article was automatically imported from the source. Read full article at original source →