250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms
Two unrelated healthcare organizations — Clover Health Investments of Jersey City, New Jersey, and AngMar Management Services of Mansfield, Texas — have separately disclosed data breaches that together affect more than 264,000 people, exposing Social Security numbers, diagnosis details, and other protected health information. Clover Health reported 138,677 affected individuals after attackers used social engineering to compromise three employee accounts, while AngMar Management Services reported 126,196 affected individuals after the Interlock ransomware group claimed to have stolen over 700 gigabytes of data from its systems.
Details
| Attribute | Value |
|---|---|
| Company 1 | Clover Health Investments (Jersey City, NJ) |
| Company 1 — Discovery | Early July 2026 |
| Company 1 — Method | Social engineering compromised 3 non-managerial employee accounts |
| Company 1 — Individuals Notified to HHS | 138,677 (mid-September 2026) |
| Company 2 | AngMar Management Services (Mansfield, TX) |
| Company 2 — Discovery | Mid-July 2026 (confirmed early September) |
| Company 2 — Method | Network intrusion; data theft claimed by Interlock ransomware group |
| Company 2 — Data Claimed Stolen | 700+ GB, posted to Interlock's Tor leak site in August 2026 |
| Company 2 — Individuals Notified to HHS | 126,196 (September 16, 2026) |
| Combined Individuals Affected | Over 264,000 |
| Data Exposed | Names, birth dates, Social Security numbers, diagnosis details, medical history, health insurance information, patient IDs, provider names, prescription details, dates of service |
Clover Health Investments: Social Engineering Targets Scheduling and Sales Staff
Clover Health Investments, a Medicare Advantage insurer, was breached in early July 2026 after attackers used social engineering to gain access to three employee accounts. According to the company's SEC filing, the compromised accounts belonged to non-managerial staff with member visit-scheduling and broker-facing sales functions — roles that had access to certain personally identifiable information (PII) and protected health information (PHI), but no access to corporate financial or claims systems. Clover notified the Department of Health and Human Services (HHS) in mid-September that 138,677 individuals were affected. The company has not disclosed the identity of the threat actor, and no known ransomware or extortion group has claimed responsibility for the intrusion.
AngMar Management Services: Interlock Ransomware Claims 700GB Theft
AngMar Management Services provides back-office business operations, administration, and support network management for home health and hospice care providers. The company identified suspicious activity on its systems in mid-July 2026 and confirmed in early September that hackers had stolen patient PII and PHI. The Interlock ransomware group added AngMar to its Tor-based leak site in August 2026, claiming to have exfiltrated more than 700 gigabytes of data. AngMar notified HHS on September 16, 2026 that 126,196 individuals were affected.
Shared Exposure Profile
Despite being unrelated incidents at unconnected companies, the categories of data exposed overlap significantly: names, dates of birth, Social Security numbers, diagnosis and medical history details, health insurance information, patient IDs, treating-provider names, prescription information, and dates of service. That combination gives attackers everything needed for medical identity theft, insurance fraud, and highly convincing targeted phishing against affected patients.
Impact Assessment
| Impact Area | Description |
|---|---|
| Patient Privacy | Over 264,000 individuals had Social Security numbers and detailed medical history exposed across the two incidents |
| Fraud Risk | SSNs combined with insurance and provider data enable medical identity theft and fraudulent billing schemes |
| Vendor Risk | AngMar's role as a back-office administrator for home health and hospice providers means downstream patients and provider organizations are affected despite having no direct relationship with AngMar |
| Insider-Adjacent Access | Clover's breach shows that even staff without claims or financial system access can hold enough PII/PHI to trigger a large-scale notification |
| Extortion Exposure | AngMar's data was posted to a ransomware leak site, increasing the likelihood of secondary exploitation or sale |
Recommendations
For Healthcare Organizations and Business Associates
- Apply phishing-resistant MFA (e.g., FIDO2/passkeys) to all employee accounts, not just those with system-administrator or claims-system access — Clover's scheduling and sales staff still held exposed PII/PHI
- Segment access so that customer-facing and scheduling roles cannot retrieve bulk patient records beyond what's needed for a single interaction
- Treat business associates and back-office vendors (like AngMar) as part of the organization's attack surface; downstream breach notifications fall on the covered entity's patients regardless of which party was compromised
- Maintain offline, tested backups and an incident response plan specific to ransomware data-theft extortion, where encryption may not even occur before data is leaked
For Affected Patients
- Place a fraud alert or credit freeze given that Social Security numbers were exposed in both incidents
- Watch for Explanation of Benefits (EOB) statements for services never received, a common sign of medical identity theft
- Be cautious of follow-up phishing attempts referencing real diagnosis or provider details drawn from the stolen data — these increase the credibility of social engineering attempts
For Security and Compliance Teams
- Review HIPAA Business Associate Agreements to confirm breach notification timelines and security obligations are enforceable and monitored, not just contractually assumed
- Audit which employee roles can access PHI in bulk versus record-by-record, and apply rate-limiting or anomaly detection to bulk-access patterns
Key Takeaways
- Clover Health Investments and AngMar Management Services disclosed separate, unrelated healthcare data breaches affecting a combined total of over 264,000 individuals.
- Clover's breach stemmed from social engineering that compromised three non-managerial employee accounts with scheduling and sales access; no threat actor has claimed responsibility.
- AngMar's breach was claimed by the Interlock ransomware group, which posted over 700GB of allegedly stolen data to its leak site.
- Exposed data across both incidents includes Social Security numbers, diagnosis and medical history details, insurance information, and prescription data — a combination that enables medical identity theft and fraud.
- Both companies notified HHS in September 2026, and are actively notifying affected patients while reinforcing their security defenses.