Clover Health Investments, Corp. disclosed a cybersecurity incident detected on July 4, 2026, where a threat actor gained unauthorized access to certain company systems. The company has contained the incident and stated that it does not believe it will have a material impact on its business, financial condition, or results of operations.

Key Details

  • Incident: On July 4, 2026, a threat actor gained access to three non-managerial health plan employee accounts through social engineering.
  • Data Exposure: The compromised accounts had access to certain member personally identifiable information (PII) and protected health information (PHI), but not to corporate financial or claims systems.
  • Company Response: Clover Health activated its incident response plan, engaged third-party cybersecurity experts, notified law enforcement, and believes it has successfully contained the unauthorized access. The investigation remains ongoing.