NEWS

250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms

Clover Health Investments and AngMar Management Services separately disclosed breaches exposing PII and PHI for over 250,000 people combined.

Dylan H.

News Desk

October 5, 2026
6 min read
250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms

250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms

Two unrelated healthcare organizations — Clover Health Investments of Jersey City, New Jersey, and AngMar Management Services of Mansfield, Texas — have separately disclosed data breaches that together affect more than 264,000 people, exposing Social Security numbers, diagnosis details, and other protected health information. Clover Health reported 138,677 affected individuals after attackers used social engineering to compromise three employee accounts, while AngMar Management Services reported 126,196 affected individuals after the Interlock ransomware group claimed to have stolen over 700 gigabytes of data from its systems.


Details

AttributeValue
Company 1Clover Health Investments (Jersey City, NJ)
Company 1 — DiscoveryEarly July 2026
Company 1 — MethodSocial engineering compromised 3 non-managerial employee accounts
Company 1 — Individuals Notified to HHS138,677 (mid-September 2026)
Company 2AngMar Management Services (Mansfield, TX)
Company 2 — DiscoveryMid-July 2026 (confirmed early September)
Company 2 — MethodNetwork intrusion; data theft claimed by Interlock ransomware group
Company 2 — Data Claimed Stolen700+ GB, posted to Interlock's Tor leak site in August 2026
Company 2 — Individuals Notified to HHS126,196 (September 16, 2026)
Combined Individuals AffectedOver 264,000
Data ExposedNames, birth dates, Social Security numbers, diagnosis details, medical history, health insurance information, patient IDs, provider names, prescription details, dates of service

Clover Health Investments: Social Engineering Targets Scheduling and Sales Staff

Clover Health Investments, a Medicare Advantage insurer, was breached in early July 2026 after attackers used social engineering to gain access to three employee accounts. According to the company's SEC filing, the compromised accounts belonged to non-managerial staff with member visit-scheduling and broker-facing sales functions — roles that had access to certain personally identifiable information (PII) and protected health information (PHI), but no access to corporate financial or claims systems. Clover notified the Department of Health and Human Services (HHS) in mid-September that 138,677 individuals were affected. The company has not disclosed the identity of the threat actor, and no known ransomware or extortion group has claimed responsibility for the intrusion.

AngMar Management Services: Interlock Ransomware Claims 700GB Theft

AngMar Management Services provides back-office business operations, administration, and support network management for home health and hospice care providers. The company identified suspicious activity on its systems in mid-July 2026 and confirmed in early September that hackers had stolen patient PII and PHI. The Interlock ransomware group added AngMar to its Tor-based leak site in August 2026, claiming to have exfiltrated more than 700 gigabytes of data. AngMar notified HHS on September 16, 2026 that 126,196 individuals were affected.

Shared Exposure Profile

Despite being unrelated incidents at unconnected companies, the categories of data exposed overlap significantly: names, dates of birth, Social Security numbers, diagnosis and medical history details, health insurance information, patient IDs, treating-provider names, prescription information, and dates of service. That combination gives attackers everything needed for medical identity theft, insurance fraud, and highly convincing targeted phishing against affected patients.


Impact Assessment

Impact AreaDescription
Patient PrivacyOver 264,000 individuals had Social Security numbers and detailed medical history exposed across the two incidents
Fraud RiskSSNs combined with insurance and provider data enable medical identity theft and fraudulent billing schemes
Vendor RiskAngMar's role as a back-office administrator for home health and hospice providers means downstream patients and provider organizations are affected despite having no direct relationship with AngMar
Insider-Adjacent AccessClover's breach shows that even staff without claims or financial system access can hold enough PII/PHI to trigger a large-scale notification
Extortion ExposureAngMar's data was posted to a ransomware leak site, increasing the likelihood of secondary exploitation or sale

Recommendations

For Healthcare Organizations and Business Associates

  • Apply phishing-resistant MFA (e.g., FIDO2/passkeys) to all employee accounts, not just those with system-administrator or claims-system access — Clover's scheduling and sales staff still held exposed PII/PHI
  • Segment access so that customer-facing and scheduling roles cannot retrieve bulk patient records beyond what's needed for a single interaction
  • Treat business associates and back-office vendors (like AngMar) as part of the organization's attack surface; downstream breach notifications fall on the covered entity's patients regardless of which party was compromised
  • Maintain offline, tested backups and an incident response plan specific to ransomware data-theft extortion, where encryption may not even occur before data is leaked

For Affected Patients

  • Place a fraud alert or credit freeze given that Social Security numbers were exposed in both incidents
  • Watch for Explanation of Benefits (EOB) statements for services never received, a common sign of medical identity theft
  • Be cautious of follow-up phishing attempts referencing real diagnosis or provider details drawn from the stolen data — these increase the credibility of social engineering attempts

For Security and Compliance Teams

  • Review HIPAA Business Associate Agreements to confirm breach notification timelines and security obligations are enforceable and monitored, not just contractually assumed
  • Audit which employee roles can access PHI in bulk versus record-by-record, and apply rate-limiting or anomaly detection to bulk-access patterns

Key Takeaways

  1. Clover Health Investments and AngMar Management Services disclosed separate, unrelated healthcare data breaches affecting a combined total of over 264,000 individuals.
  2. Clover's breach stemmed from social engineering that compromised three non-managerial employee accounts with scheduling and sales access; no threat actor has claimed responsibility.
  3. AngMar's breach was claimed by the Interlock ransomware group, which posted over 700GB of allegedly stolen data to its leak site.
  4. Exposed data across both incidents includes Social Security numbers, diagnosis and medical history details, insurance information, and prescription data — a combination that enables medical identity theft and fraud.
  5. Both companies notified HHS in September 2026, and are actively notifying affected patients while reinforcing their security defenses.

Sources