Clover Health experienced a data breach, according to a July 17 filing with the Securities and Exchange Commission.
The insurer detected abnormal login activity on some information systems on July 4. Clover said it launched incident response procedures “immediately” and an investigation alongside third-party cybersecurity experts, as well as informed law enforcement.
Clover learned a threat actor secured access to three nonmanagerial health plan employee accounts via social engineering. The exposed accounts were linked to employees with member visit-scheduling and broker-facing sales work. While they had access to some personally identifiable information and protected health information, these employees could not reach corporate financial or claims systems. The company anticipates the threat has been contained and there is likely no effect on the business. The investigation is ongoing, according to the filing.
“The company takes the privacy and security of its member data very seriously and has taken, and continues to take, steps to further harden its IT environment,” the filing said. “The company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted members.”
At the Becker's 5th Annual Fall Payer Issues Roundtable, taking place November 2–3 in Chicago, payer executives and healthcare leaders will come together to discuss value-based care, regulatory changes, cost management strategies and innovations shaping the future of payer-provider collaboration. Apply for complimentary registration now.
