Over 250,000 people’s sensitive medical information has been stolen in a pair of data breaches that hit two separate healthcare companies in New Jersey and Texas. The incidents highlight the ongoing threat of cyber attacks against healthcare organizations, which hold vast amounts of personal and protected health information.
Clover Health Investments, based in Jersey City, New Jersey, was hacked in early July after attackers used social engineering tactics to compromise three non-managerial employee accounts. The breach resulted in the theft of personally identifiable information (PII) and protected health information (PHI), including names, dates of birth, insurance identifiers, and account identification numbers.
In mid-September, Clover Health Investments notified the US Department of Health and Human Services (HHS) that 138,677 people were affected. The company was added to HHS’s data breaches portal last week, a database that tracks incidents affecting 500 or more individuals. This is not the first time Clover Health has been targeted by attackers; in 2022, the company reported a breach involving unauthorized access to patient data.
AngMar Management Services, based in Mansfield, Texas, also fell victim to a data breach after hackers stole patient PII and PHI. The impacted information includes names, birth dates, Social Security numbers, diagnosis details, medical history data, health insurance information, patient IDs, provider names, prescription details, and dates of service. In mid-July, AngMar Management Services identified suspicious activity on its systems but didn’t confirm the breach until early September.
The Interlock ransomware group has claimed to have stolen over 700 gigabytes of data from AngMar Management Services and added the company to its Tor-based leak site in August. On September 16, AngMar Management Services notified HHS that 126,196 individuals were affected. The company was also added to HHS’s data breaches portal last week.
The scale of these breaches is alarming, but it’s essential for healthcare companies to prioritize cybersecurity measures to prevent similar incidents. This includes implementing robust security protocols, conducting regular vulnerability assessments, and providing employee training on social engineering tactics.
For individuals whose information has been compromised, vigilance is key. It’s crucial to monitor your medical accounts and credit reports closely for any suspicious activity. If you suspect that your data has been stolen, report the incident to your healthcare provider or relevant authorities immediately.
As these breaches demonstrate, healthcare organizations are increasingly vulnerable to cyber attacks. To mitigate this risk, companies must invest in robust security measures and prioritize employee education on cybersecurity best practices.
Source: SecurityWeek — 2026-10-05