Security1 publisher2 min readPublished
Clover Health and hospice back-office vendor AngMar report breaches affecting 264,873 people
Clover Health and AngMar Management Services have reported breaches affecting a combined 264,873 people to HHS. Clover's began with social engineering of staff accounts, while AngMar's took patient records it held for home health and hospice providers.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Clover disclosed the theft of personal and protected health information in an SEC filing in July.
- HHS heard from Clover in mid-September that 138,677 people were affected and added the company to its breach portal last week.
- AngMar's stolen data includes Social Security numbers, diagnosis details, medical history, health insurance information and prescription details.
- The Interlock ransomware group listed AngMar on its Tor-based leak site in August and claimed to have taken more than 700 gigabytes.
- AngMar, which spotted suspicious activity in mid-July, notified HHS on September 16 that 126,196 individuals were affected.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Clover's attackers needed only three non-managerial logins, so a health plan's security spending has to cover how ordinary staff are targeted and how fast a misused account is caught.
- exposure Home health and hospice providers that hand administration to a firm like AngMar have their patients' identity and clinical records exposed by a breach outside their own organisations.
- constraint With Interlock named only at AngMar, the two cases are evidence about entry points, and treating them as one campaign would go beyond the record.
Clover's attackers got in through three non-managerial health plan employee accounts in early July [2]. The company listed names, dates of birth, insurance identifiers and account identification numbers as potentially affected [4]. Social Security numbers appear on AngMar's list and not on Clover's [3].
AngMar does a different job and held different data. It runs business operations, administration and support network management for home health and hospice care providers [7]. Its stolen set links patients to provider names, patient IDs and dates of service [8]. The breach happened at AngMar, one step removed from the providers whose patients are in the file [6][7].
Interlock went public first. The group's August leak-site listing came before AngMar confirmed in early September that hackers had stolen patient data [2]. The figure of more than 700 gigabytes is Interlock's own claim, as reported by SecurityWeek [9].
The two breaches are separate [1]. Interlock is the only group named in either case, and it is named only for AngMar [9]. On this record they are two unrelated entry points into US health data. One is ordinary staff identities at a health plan. The other is a vendor holding records for the providers it serves [2][7].
In my view that supports putting staff-account defences and vendor oversight on the same footing as network defences. The evidence for the narrower help-desk version of the argument is thinner. SecurityWeek's report does not say whether the social engineering at Clover went through a help desk, email or phone, or how attackers reached AngMar's systems.
What to watch
- Whether Interlock publishes data from the more than 700 gigabytes it claims to hold from AngMar.
- Whether Clover's SEC filings or AngMar's notices name the social-engineering channel or the initial access route.
- Whether home health and hospice providers that used AngMar file their own notifications or the 126,196 count is revised.