All Breaches
July 4, 2026 Verified Sensitive Record Healthcare

Clover Health 2026 Data Breach

The Clover Health 2026 data breach was an incident in which a threat actor gained unauthorized access through social engineering to three non-managerial health-plan employee accounts at a Medicare Advantage health-insurance and technology company. Clover Health Investments, Corp. detected anomalous login activity on certain information systems on July 4, 2026, and disclosed the event in a Form 8-K filed with the U.S. Securities and Exchange Commission.

According to preliminary findings, the accounts belonged to employees performing member visit-scheduling and broker-facing sales functions and could access certain personally identifiable information and protected health information. They had no access to corporate financial or claims systems. The investigation was ongoing, and no affected-person total or specific data fields were published. LeakData keeps pwnCount and totalRecords at zero; importedRecordCount is also zero.

How Was the Clover Health Breach Confirmed?

The primary evidence is Clover Health Investments' current report on Form 8-K published through the SEC EDGAR system. The company-signed filing directly identifies the anomalous logins, incident response, three employee accounts compromised through social engineering, the functions of those accounts, broad data classes they could access, and systems they could not reach.

The SEC record is an official primary source; it lists July 4 as the earliest event date and was signed on July 17, 2026. Claim Depot independently tracks the public filing and summarizes the PII and PHI scope. LeakData relies on the 8-K for details and does not treat illustrative examples in a secondary explanation as confirmed incident fields.

What Happened on July 4, 2026?

Clover Health observed anomalous login activity on certain information systems. The company immediately activated incident-response procedures, initiated an investigation with leading third-party cybersecurity specialists, took steps to contain the activity, and notified law enforcement. The official disclosure says the company believed its rapid response successfully contained and terminated the unauthorized access.

The investigation found that a threat actor used social engineering to access three non-managerial health-plan employee accounts. The public filing does not say whether the social engineering used a telephone call, email, fake login page, or another method. It also does not identify whether a password, session token, or another authentication element was obtained.

Which Accounts and Systems Were Affected?

The affected accounts were assigned to employees performing member visit-scheduling and broker-facing sales functions. That business context explains why the accounts could reach some member information, but it does not mean each account held the same records or permission level. The company was still examining the precise nature, scope, and extent of data subject to unauthorized access and acquisition.

The 8-K also establishes an important boundary: the employee accounts had no access to corporate financial or claims systems. It would therefore be unsupported to say that Clover's financial statements, corporate banking data, or the entire insurance-claims database was exposed through those accounts. LeakData records the confirmed account access without extending the scope to systems the company excluded.

What Personal and Health Data Was In Scope?

The company confirmed only that the accounts had access to certain personally identifiable information and protected health information. The 8-K does not list individual fields such as names, addresses, dates of birth, Social Security numbers, Medicare identifiers, diagnoses, treatments, prescriptions, or policy numbers.

PII and PHI are broad legal and operational categories. An account's ability to access those categories does not prove that every possible field was viewed or acquired. Claim Depot explains the categories with general examples but also says the specific elements in this incident were not publicly confirmed. LeakData therefore limits its data classes to “Personal information” and “Protected health information.”

How Many People Were Affected and What Was the Impact?

Clover Health had not published a nationwide total of affected people or notification recipients. The count of three employee accounts does not mean three people or three records were affected; the number of members accessible through an account is unknown. LeakData does not estimate that scale, keeps pwnCount and totalRecords at zero, and imports no member rows.

Based on information available as of the filing, the company said it did not believe the incident had, or was reasonably likely to have, a material impact on its business, financial condition, or results of operations. That is a corporate materiality assessment under securities law; it does not mean the member data is insensitive or that no individual risk exists.

How Did Clover Health Respond and What Should Members Do?

Clover Health activated incident response, worked with outside cybersecurity specialists, notified law enforcement, contained the access, and said it had taken steps to further harden its IT environment. The company said it would continue investigating the exact scope, evaluating regulatory and legal notice requirements, and making required notifications to affected members based on its findings.

Clover Health members should watch for notices through official channels and should not provide passwords, Medicare details, health information, or verification codes in unexpected visit-scheduling or broker messages. Healthcare-portal activity and insurance explanation-of-benefits statements can be reviewed for unfamiliar services. LeakData does not host or make searchable account data, member records, or leaked files from the event.

0
Affected Accounts
2
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

2
Personal information
Protected health information

Additional Information

Added DateJuly 27, 2026
Breach DateJuly 4, 2026
Domaincloverhealth.com
SourceClover Health SEC Form 8-K confirming social-engineering access to three employee accounts with PII and PHI access
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information