Two healthcare organizations in New Jersey and Texas are notifying more than 250,000 patients that their personal and medical information was stolen in separate July cyber incidents involving Clover Health Investments and AngMar Management Services[1]. Clover Health, a Jersey City–based Medicare Advantage plan provider, and Mansfield, Texas–based AngMar, which manages home health and hospice agencies, have both reported theft of personally identifiable information and protected health information to federal regulators[1][4][12].
Clover Health said it detected anomalous login activity on July 4 and later determined that a threat actor had gained access to three non‑managerial health plan employee accounts through social engineering techniques[5][11][13]. Those accounts, used for member visit scheduling and broker-facing sales, had access to certain personally identifiable information and protected health information but not to corporate financial or claims systems, according to the company’s Form 8‑K filing with the U.S. Securities and Exchange Commission[11][15]. Clover told the Department of Health and Human Services in mid‑September that 138,677 individuals were affected, although its investigation into the precise nature and scope of the compromised data is still ongoing[1][5][11].
AngMar Management Services reported that it identified unusual activity in its network on July 20 and that a subsequent forensic investigation found an unauthorized actor had accessed or acquired files containing patient information around July 18[7][8][14]. The Texas hospice management firm, which oversees nearly 100 home health and hospice locations across multiple states, said the review of affected data confirmed exposure of names, addresses, dates of birth, Social Security numbers, patient IDs, medical record numbers, health insurance details, dates of service, diagnoses and conditions, provider names, prescription information and medical histories[4][10][14]. AngMar later notified federal regulators that 126,196 individuals were impacted, including at least 35,916 Texas residents whose personal and protected health information may have been compromised[1][4][14].
The incident at AngMar appears to be linked to the Interlock ransomware group, which added the company to its dark‑web leak site in August and claimed to have exfiltrated approximately 700–710 gigabytes of data from its systems[1][7][14]. While Clover Health has not publicly attributed its breach to a specific threat group and has characterized the incident as contained with no material impact on its business, both cases underscore how social engineering and data exfiltration campaigns continue to drive healthcare‑focused cybercrime[5][11][13].
The disclosures have already prompted scrutiny from regulators and plaintiffs’ firms, with multiple legal investigations exploring potential class‑action claims on behalf of patients whose data was exposed in the Clover and AngMar incidents[3][12][13]. Individuals affected in these breaches face heightened risks of identity theft, tax and benefits fraud, and highly sensitive medical information being misused or published on criminal forums, particularly in ransomware cases where threat actors threaten to leak data to pressure victims into paying[1][4][7].
For healthcare organizations, the twin breaches highlight the need to harden employee accounts against social engineering, enforce multi‑factor authentication, and limit the amount of sensitive member data accessible from front‑line systems. Robust network monitoring, rapid incident response and clear communication with affected patients are also critical, as attackers increasingly combine credential theft with large‑scale data exfiltration to maximize their leverage and impact.
References
- 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms
- AngMar Management Service Data Breach Investigation
- AngMar Management Services Data Breach Impacts 126k Individuals
- Clover Health Investments Discloses Data Breach
- Angmar Management Services Data Breach Investigation
- Notice of Security Incident
- AngMar Management Services Data Breach Investigation | Almeida Law Group
- Form 8-K for Clover Health Investments Corp DE filed …
- AngMar Management Services Data Breach Lawsuit
- Clover Health Data Breach Affects Sensitive Info
- Texas Hospice Management Company Data Breach Affects 35,000 Texas Residents
- Clover Health discloses cyber incident in 3 accounts
