PrivacySignal
Healthcare

Clover Health Assessing Impact of Social Engineering Incident

HIPAA Journal · · US Federal · Healthcare Privacy

Clover Health Investments has filed an SEC disclosure reporting a cybersecurity incident, identified in July, that involved social engineering. The company says it is still assessing the scope and impact of the breach.

Why this matters: Clover Health covers Medicare Advantage members, which means the data at risk is not generic. It is health records, claims history, and personal details belonging to older adults who did not choose to store that information with a tech company — it came with their insurance plan. Social engineering means someone was tricked into handing over access, which is a people problem, not just a software problem. The SEC filing is public, but the details patients actually need — what was taken and whether they are affected — are still unclear.

Who should care: Healthcare professionals · Privacy officers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Healthcare
HIPAA Journal · · US Federal

Major Healthcare Software Vendor Investigating Cyberattack

Craneware, a healthcare technology company that provides financial and operational software to hospitals and health systems, is investigating a cyberattack and has confirmed that a significant volume of data was compromised. The full scope of the breach has not yet been disclosed.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

HHS Seeks Input on Potential Updates to the CLIA Regulations

The U.S. Department of Health and Human Services, through CMS and the CDC, has issued a request for public input on possible updates to the Clinical Laboratory Improvement Amendments regulations, which govern quality standards for laboratory testing across the country.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers

#healthcare#regulation Read original →
Healthcare
Inside Privacy (Covington) · · International

OMB Publishes 2026 Unified Agenda Signaling Upcoming Health Privacy and Interoperability Updates from HHS

The Office of Management and Budget has published its 2026 Unified Agenda, laying out the regulatory actions federal agencies plan to propose or finalize this year. Among the items flagged are several HHS rules touching on health privacy, interoperability, and data exchange.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers · General readers · Policy

#healthcare#regulation#privacy Read original →
Healthcare
HIPAA Journal · · US Federal

Abbott Investigating Cyberattack Claims From Two Threat Actors

The healthcare giant Abbott is investigating claims from two threat groups who allege cyberattacks and data theft, one involving legacy […] The post Abbott Investigating Cyberattack Claims From Two Threat Actors appeared first on The HIPAA Journal.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare#security Read original →
Healthcare
TechCrunch — Privacy · · International

Period tracker Stardust shares users’ health data with analytics firm, says Mozilla research

Mozilla research found that Stardust, a period tracking app, shares users' health data with a third-party analytics firm. The findings reveal significant variation in privacy practices across period tracker apps, with at least one app handling data responsibly while Stardust did not.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · Policy

#healthcare#privacy Read original →
Healthcare
HIPAA Journal · · US Federal

Ohio Living; Erlanger; Heart of America Eye Care Announce Data Breaches

Three healthcare organizations — Ohio Living, a senior living provider, Erlanger Health System in Tennessee, and Heart of America Eye Care — have each disclosed separate data breaches. All three operate in sectors covered by HIPAA, meaning the compromised data likely includes sensitive medical and personal information.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →