# Clover Health Data Breach Exposes Sensitive Information

*Published July 26, 2026*
*Source: [https://www.securityweek.com/clover-health-investments-discloses-data-breach/](https://www.securityweek.com/clover-health-investments-discloses-data-breach/)*

## Executive Summary

Clover Health Investments has disclosed a data breach resulting from a social engineering attack that compromised employee accounts, exposing customer personal and health information. The company is investigating the breach's scope while ensuring system security with the help of cybersecurity experts.

## Article

Clover Health Investments, a healthcare technology company, has reported a data breach that exposed personal and health information of its customers. The breach was discovered on July 4 and originated from a social engineering attack targeting three non-managerial employee accounts. These accounts were used by employees responsible for member visit scheduling and broker-facing sales functions, which provided access to certain personally identifiable information and protected health information. However, they did not have access to the company’s corporate financial or claims systems.

Upon discovering the breach, Clover Health immediately implemented its response plan and enlisted the help of third-party cybersecurity experts to contain and investigate the incident. While the company managed to evict the attackers from its systems, it is still working to fully understand the scope and impact of the breach. As of now, the identity of the threat actor remains unknown, and no ransomware or extortion group has taken responsibility for the attack.

Clover Health, founded in 2014, is known for providing Medicare Advantage insurance plans and operates as a direct contractor for the US government. The company has yet to disclose further details about the breach, and efforts to obtain more information are ongoing.
