BreachesMedium

Two US healthcare firms disclose July breaches affecting nearly 265,000 people

Clover Health Investments and AngMar Management Services reported separate July intrusions to US federal regulators, exposing insurance identifiers, Social Security numbers and medical histories.

Two US healthcare firms disclose July breaches affecting nearly 265,000 people

At a glance

  • Clover Health Investments reported 138,677 people affected after three employee accounts were compromised through social engineering in early July
  • AngMar Management Services reported 126,196 people affected; the Interlock ransomware group claimed to have stolen more than 700 GB of data
  • Exposed records include Social Security numbers, diagnosis details, prescription information and medical history
  • Both incidents were reported to the US Department of Health and Human Services in September and added to its public breach portal late that month

Two separate cyber incidents at US healthcare organisations in July have exposed the personal and medical data of a combined 264,873 people, according to SecurityWeek. New Jersey-based health insurer Clover Health Investments and Texas-based home health and hospice management firm AngMar Management Services both notified the US Department of Health and Human Services (HHS) in September, and SecurityWeek reports that both breaches were added to the department's public breach portal in late September.

What happened

SecurityWeek reports that the Clover Health incident occurred in early July and affected 138,677 individuals, with the company notifying HHS in mid-September. AngMar Management Services detected suspicious activity on its network in mid-July, confirmed the breach in early September and reported it to HHS on 16 September. That incident affected 126,196 people.

Neither organisation has described the two events as related, and SecurityWeek does not link them to a single actor or campaign.

Clover Health: three staff accounts compromised

According to SecurityWeek, the Clover Health breach began when three non-managerial employee accounts were compromised through social engineering. The company also disclosed the incident to the US Securities and Exchange Commission in July.

The data involved includes names, dates of birth, insurance identifiers, account identification numbers and other personally identifiable information and protected health information, SecurityWeek reports.

AngMar: Interlock claimed more than 700 GB

The AngMar incident carries a heavier data set. SecurityWeek reports that the exposed records include names, dates of birth, Social Security numbers, diagnosis details, medical history, health insurance information, patient IDs, provider names, prescription details and dates of service.

The Interlock ransomware group claimed responsibility for the theft of more than 700 gigabytes of AngMar data and posted the company on its leak site in August, according to SecurityWeek. The company itself has not publicly confirmed the group's claims about the volume of stolen data, and the figure comes from the attackers rather than from an independent review.

Who is affected and what to do

The AngMar data set is the more damaging of the two, because Social Security numbers combined with diagnosis and prescription details support both financial identity fraud and highly convincing targeted fraud. Anyone who has received a notification letter from either organisation should treat unexpected calls, emails or texts referencing their treatment, insurance or billing as suspect, and should verify any such contact through a phone number they look up themselves.

People whose Social Security number was involved should consider placing a credit freeze with the major US credit bureaus rather than relying on monitoring alone, since a freeze blocks new account openings outright. Checking the HHS breach portal entry for the relevant organisation is the most reliable way to confirm the scope of each incident, as notification letters are sent in batches and may arrive weeks apart.

For healthcare providers and their service partners, the Clover Health case is a reminder that an intrusion does not require a software vulnerability: three ordinary staff accounts were enough. Phishing-resistant multi-factor authentication on all employee accounts, not only administrative ones, remains the most effective control against this access route.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.