SecurityWeek reported on 5 October that two US healthcare firms are warning people about separate data thefts. Clover Health Investments, of Jersey City, New Jersey, said in a July SEC filing that attackers used social engineering, meaning trickery aimed at people, to compromise three non-managerial health plan employee accounts. In mid-September, Clover gave the US health department (HHS) a figure of 138,677 affected people. AngMar Management Services, of Mansfield, Texas, reported 126,196 to HHS on September 16. That adds up to 264,873 people across the two cases.
Clover said the data at risk includes names, birth dates, insurance identifiers and account numbers. AngMar handles back-office support for home health and hospice providers. It confirmed in early September that patient data was stolen, including Social Security numbers, diagnoses and prescription details. Interlock, a ransomware group, listed AngMar in August on its leak site, where it names victims, and claimed over 700 gigabytes. That is the group's own claim. The sources do not say how AngMar was breached or who attacked Clover.
This is our reading, not a finding in the reports. Clover's case shows that three ordinary accounts were enough to reach sensitive data. Budget owners can ask what one such account can reach, and how much patient data each vendor holds.