Clover Health, a publicly traded Medicare Advantage insurer, has reported a hacking incident to the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR). The filing says the protected health information (PHI) of 138,677 people was compromised. Two secondary sources that summarise the HHS filing (databreachrights.com and the law firm Federman & Sherwood) both give the 138,677 figure, so the record count is consistent across the reporting. Federman & Sherwood says the report reached HHS on September 14, 2026. Earlier company disclosures, as summarised by Health Quest NF, said an attacker used social engineering to take over three employee accounts in July. Four proposed class actions have followed. No source available for this brief is a primary document such as the HHS portal entry, the SEC filings, or the member notification letters, so the details below are attributed to the outlet that reported them.
What Happened
The reported timeline, put together from the available sources:
- July 4: Clover detected unusual login activity on some of its information systems, according to Health Quest NF's summary of the company's SEC disclosures.
- July 17: Clover publicly disclosed the cybersecurity incident in an SEC filing. The company said third-party cybersecurity experts found that a threat actor had used social engineering to get into three nonmanagerial health plan employee accounts. Those employees worked in member visit scheduling and broker-facing sales. Clover said it believes it contained and ended the unauthorized access, that it notified law enforcement, and that it began strengthening its IT environment.
- July 22 to 24: Four proposed class actions were filed in the U.S. District Court for the Middle District of Tennessee, starting with Christian et al. v. Clover Health Investments. The suits allege negligence, unjust enrichment, and breach of implied contract. In its Q2 filing, Clover said it would "vigorously defend these matters" and could not estimate potential losses.
- September 14, 2026: Clover submitted its HHS OCR breach report, classified as a "Hacking/IT Incident" affecting 138,677 individuals, according to Federman & Sherwood. Databreachrights.com dates the notification to September 2026 and says the discovery date was not publicly disclosed.
Two caveats apply. First, none of the sources explicitly ties the July social engineering incident to the September HHS filing. The link is very likely, because the company is the same and the timing and lawsuits line up, but it is an inference. Second, the HHS filing reportedly lists the breach location as "network server" and "other." That fits awkwardly with the SEC description of compromised employee accounts. It may simply reflect how the HHS form categorises account-based access. As of Health Quest NF's reporting, Clover had not said how many members were affected. The HHS figure appears to be the first public count.
What Was Taken
Accounts differ on which data was exposed, and none of the available sources confirms specific fields.
- Federman & Sherwood states that the HHS filing does not identify the categories of information affected. It lists names, Social Security numbers, medical information, and health insurance information only as data that "may" have been involved.
- Databreachrights.com contradicts itself. Its text says specific data fields "were not detailed publicly," but its summary table lists full names, health plan member IDs, medical or treatment information, claims data, dates of birth, and contact information. Treat that list as unverified.
- The company's SEC disclosure, per Health Quest NF, says the compromised accounts could reach "certain" PII and PHI but could not reach Clover's corporate financial or claims systems. If that holds, it conflicts with databreachrights.com's inclusion of claims data.
Whether Social Security numbers were exposed has not been confirmed. Affected members should rely on their individual notification letters for what was actually involved.
Why It Matters
Medicare Advantage members are older people, a group that fraudsters target heavily for medical identity theft, fake benefits calls, and Medicare scams. Member IDs and treatment details are useful for convincing pretexting even without financial data. The access pattern also matters. Scheduling and broker-facing sales staff are not privileged users, yet their accounts could reach member PHI. An attacker did not need administrator credentials to cause a reportable breach of more than 100,000 records.
The incident is part of a heavy run of healthcare breach disclosures. HIPAA Simple reports that health data vendor Aesto Health confirmed 9,540,683 people affected by a December 2025 intrusion into its AWS environment. Nutex Health said on September 10 that the party behind its earlier cybersecurity event had published allegedly stolen data. Neither incident is connected to Clover.
A note on naming: recent coverage of an "OpenAI Medicare hack" (ABC News, The Record) concerns an AI agent reaching files on an Australian government Medicare statistics portal run by Services Australia. Australia's government says no personal Medicare details were accessed, and The Record reports that researchers question whether a "hack" happened at all, since archived site code pointed visitors to an unauthenticated endpoint. That story has nothing to do with Clover Health or U.S. Medicare Advantage.
The Attack Technique
According to Health Quest NF's summary of Clover's SEC disclosures, the confirmed method is social engineering that led to employee account takeover. No malware, exploited vulnerability, or named threat group has been reported, and no group appears to have claimed the attack.
IPBan, a security vendor blog, describes the intrusion as starting with a phone call, with someone talking their way past an employee. It argues the case fits the help-desk pattern of password reset or MFA re-enrollment fraud that has been used against casinos, airlines, and telecoms. That is a reasonable hypothesis, but neither the vendor nor the other sources quote any company statement confirming voice phishing or help-desk abuse. Treat the specific delivery method as unconfirmed. What is known: three accounts were compromised, the access was detected through anomalous login activity, and it was reportedly limited to the permissions those roles held.
What Organizations Should Do
- Make help desk identity verification a hard control. Require out-of-band callback to a number already on file, manager approval, or in-person or video verification before any password reset, MFA re-enrollment, or new device registration.
- Deploy phishing-resistant MFA. FIDO2 or passkeys stop many credential relay and push-fatigue attacks that work against SMS or app-push MFA.
- Cut PHI access for front-line roles to what they need. Scheduling and sales staff should see only the fields their workflows require, through scoped views rather than broad record access, and with limits on how many records they can view.
- Alert on anomalous logins and bulk record access. Clover reportedly caught this through unusual login activity. Pair impossible-travel and new-device alerts with volume-based detection on PHI lookups and exports.
- Run social engineering exercises against the help desk and distributed staff. Test vishing and pretexting scenarios, measure results, and treat failures as control gaps, not training gaps.
- Prepare member-facing fraud guidance. For Medicare populations, warn members to expect fake "Clover" or "Medicare" calls, to review Explanation of Benefits statements, and to consider credit freezes if Social Security numbers turn out to be involved.
Sources: Clover Health Data Breach Exposes 138K Records | What we know about the data accessed in the OpenAI Medicare hack -... | Doubts grow over claims OpenAI agent hacked Australian Medicare por... | Clover Health Data Breach – Investigated by Federman & Sherwood | Clover Health Faces Four Class-Action Lawsuits Over Breach - Health... | Aesto Health Breach Hits 9.54 Million Patients | How A Phone Call Breached Clover Health's Records | NUTEX HEALTH PROVIDES UPDATE REGARDING CYBERSECURITY EVENT