Clover Health Data Breach Exposes Protected Health Information

Published: 2 October 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Clover Health, a Medicare Advantage health plan, notified HHS that a hacking incident compromised the protected health information of 138,677 individuals. The breach involved network servers and other systems, though specific data fields were not detailed publicly. Affected members should monitor credit reports, watch Explanation of Benefits statements for unfamiliar claims, and consider a credit freeze immediately.

CompanyClover Health
IndustryHealthcare
Data Types ExposedFull Names, Health Plan Member ID Numbers, Medical or Treatment Information, Health Insurance Claims Data, Dates of Birth, Contact Information
People Affected138,677 individuals
Attack MethodHacking/IT Incident
Regulators NotifiedHHS Office for Civil Rights

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Clover Health Data Breach?

Clover Health, a Medicare Advantage health plan, has confirmed a data breach that compromised sensitive member information. The company filed an official notification with the U.S. Department of Health and Human Services Office for Civil Rights. According to that filing, the incident involved a hacking or IT-related intrusion into Clover Health’s network systems.

The breach notification identifies the compromised systems as a network server, along with other unspecified storage locations. As a result, the exposure likely extended beyond a single isolated system. The exact discovery date has not been publicly disclosed. However, Clover Health submitted its formal notification in September 2026, which means the health plan had identified the intrusion by that time.

Because this incident falls under the category of a hacking or IT event, it suggests an external actor gained unauthorized access to Clover Health’s network. In response, the organization appears to have launched an internal review to determine the scope of the compromise. Details about the specific attack method, such as whether ransomware or credential theft was involved, have not been made public. As more information becomes available, affected members should watch for updates from the health plan directly.

Who was affected?

The Clover Health data breach affected 138,677 individuals, according to the organization’s filing with federal regulators. Because Clover Health operates as a Medicare Advantage health plan, those affected are likely current or former plan members. In addition, the breach could involve dependents or beneficiaries tied to those member accounts.

Given that Clover Health serves Medicare-eligible populations, many affected individuals are likely older adults. This population can be especially vulnerable to follow-up scams and fraud attempts. The geographic scope of affected individuals has not been publicly detailed beyond the health plan’s listed location in Minnesota. Therefore, members nationwide who hold or held coverage through Clover Health should consider themselves potentially impacted until they receive official confirmation.

What Information Was Potentially Exposed?

The HHS filing categorizes this event as a hacking incident affecting data stored on a network server and other systems. While the notification does not itemize every data field involved, breaches at health plans of this type typically expose a range of sensitive personal and medical information. Because Clover Health manages health coverage, member records often include both personal identifiers and plan-related details.

  • Full names
  • Health plan member identification numbers
  • Medical or treatment information
  • Health insurance claims data
  • Dates of birth
  • Contact information, including addresses and phone numbers

Specific data elements beyond these general categories have not been publicly confirmed. As a result, affected members should treat any notification letter from Clover Health as the most accurate source of detail about their own exposure.

When health plan data is compromised, the risk of medical identity theft increases significantly. For example, criminals can use stolen member ID numbers to submit fraudulent insurance claims or obtain medical services under someone else’s name. This type of fraud can be difficult to detect because it may not show up on a traditional credit report.

In addition to medical fraud, exposed personal details can fuel phishing attempts and social engineering scams. Because scammers often reference real plan information to appear legitimate, affected individuals may receive convincing fake calls or emails. This makes vigilance especially important in the months following a healthcare data breach like this one.

What is the company doing?

Clover Health took the step of formally notifying the HHS Office for Civil Rights about the breach, as required under federal health privacy law. This filing indicates the health plan recognized the incident as reportable due to the involvement of protected health information. Filing with federal regulators is typically accompanied by a broader internal investigation into the cause and scope of the breach.

Clover Health also filed formal notification with the HHS Office for Civil Rights, as required for breaches involving protected health information. Beyond this regulatory filing, the health plan has not publicly detailed every remediation step taken. Organizations in this situation often work to strengthen network defenses and monitor for further suspicious activity following disclosure.

Affected members should also watch their mail and email for a direct notification letter from Clover Health. These letters typically outline specific steps the company is taking, including any identity protection or credit monitoring services offered. Because the full scope of Clover Health’s response has not been detailed publicly beyond the regulatory filing, individuals should rely on official communications for the most accurate guidance.

What Should Affected Individuals Do?

Monitor Your Credit Reports Regularly

Affected individuals should request a free copy of their credit report from each of the three major credit bureaus. Reviewing these reports regularly can help you catch new accounts or inquiries you did not authorize. Because health plan breaches can sometimes lead to broader identity theft, this step matters even if only medical data was involved.

In addition, consider setting up ongoing credit monitoring through a reputable service. This allows you to receive alerts if someone attempts to open new credit in your name. Early detection often makes recovering from identity theft much simpler and less costly.

Consider a Fraud Alert or Credit Freeze

Because personal identifiers may have been exposed, placing a fraud alert on your credit file is a smart precaution. A fraud alert requires lenders to take extra steps to verify your identity before approving new credit. This can be done for free by contacting any one of the three major credit bureaus.

For stronger protection, you may also want to place a full credit freeze. This blocks new creditors from accessing your credit file entirely, making it much harder for identity thieves to open accounts. While a freeze requires you to temporarily lift it when applying for credit yourself, it offers the highest level of protection currently available.

Watch for Medical Identity Theft

Because this breach involved a health plan, members should pay close attention to their Explanation of Benefits statements. Review each one carefully for services or treatments you did not receive. If anything looks unfamiliar, contact Clover Health immediately to report the discrepancy.

Medical identity theft can also affect your actual medical records if a thief uses your identity to receive treatment. This could lead to incorrect information appearing in your health history. As a result, it is worth requesting a copy of your medical records periodically to confirm their accuracy.

Stay Alert for Phishing Attempts

Following a healthcare data breach, scammers often send fake emails or texts pretending to be from the affected company. These messages may ask you to click a link or provide personal information to

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

View the public data breach notification listing from HHS Office for Civil Rights

Related Data Breaches

Check other recent data breach notifications →