Clover Health, AngMar breaches hit over 250,000 people

Clover Health, AngMar breaches hit over 250,000 people

Two US healthcare organizations, Clover Health Investments and AngMar Management Services, are notifying more than 250,000 people that their personal and medical information was stolen. The two incidents are not connected, but both companies were added to the breach portal of the US Department of Health and Human Services (HHS) last week.

The HHS portal lists breaches of health information that affect 500 or more people. Organizations covered by US health privacy rules must report such incidents to the agency.

Clover Health: social engineering against employee accounts

Clover Health Investments, based in Jersey City, New Jersey, was hacked in early July. The attackers used social engineering to gain access to three health plan employee accounts. None of these accounts belonged to managers.

The company disclosed the incident in a July filing with the US Securities and Exchange Commission (SEC), the regulator that oversees publicly traded companies. In that filing, Clover Health said the attackers stole personally identifiable information (PII) and protected health information (PHI). PHI is the US legal term for health-related data that can be tied to a specific person.

The data that may have been exposed includes:

  • names
  • dates of birth
  • insurance identifiers
  • account identification numbers

In mid-September, the company told HHS that 138,677 people were affected.

AngMar: Interlock ransomware claims 700 GB

AngMar Management Services, based in Mansfield, Texas, handles business operations, administration and support network management for home health and hospice care providers.

The company spotted suspicious activity on its systems in mid-July. In early September, it confirmed that hackers had stolen patient PII and PHI.

The list of stolen data is longer than in the Clover Health case and includes more sensitive medical details:

  • names and birth dates
  • Social Security numbers
  • diagnosis details and medical history data
  • health insurance information
  • patient IDs and provider names
  • prescription details
  • dates of service

The Interlock ransomware group listed AngMar Management Services on its leak site in August. The site is hosted on Tor, the anonymity network often used by ransomware gangs to publish stolen data and pressure victims. Interlock claimed it had taken more than 700 gigabytes of data.

On September 16, AngMar notified HHS that 126,196 people were affected.

Two different paths to the same result

Taken together, the two notifications cover more than 264,000 people. The incidents also show two different ways attackers reach healthcare data.

At Clover Health, the entry point was people. Attackers tricked or manipulated staff to take over a small number of regular employee accounts, which was enough to reach member data. At AngMar, the theft was claimed by a ransomware group that uses public data leaks as leverage.

AngMar's position in the supply chain also matters. As a service provider for home health and hospice care companies, it holds patient data on behalf of other organizations. Patients of those providers may not have known the company existed before receiving a breach letter.

The Bigger Picture

For readers outside the US, these cases offer a look at how layered US breach reporting works. Clover Health first disclosed the incident to the SEC in July, then reported the number of victims to HHS two months later. That gap is common and means the full scale of an incident often becomes clear only well after the initial disclosure.

The Clover Health case suggests that MFA and account controls alone may not stop attackers who target employees directly. Similar tactics appeared in the Astrana breach, which followed phone spoofing. The AngMar incident fits a broader pattern of ransomware groups going after healthcare and its suppliers, where Social Security numbers and medical histories can be abused for fraud for years.

It is worth watching whether Interlock publishes the data it claims to hold, and whether policy changes follow. The healthcare cybersecurity bill now before the US House could put more pressure on the sector, though how much it changes remains to be seen.