2026 Healthcare Data Breaches: AngMar Management Services and Clover Health Incidents Expose 250,000 Patient Records in New Jersey and Texas

2026 Healthcare Data Breaches: AngMar Management Services and Clover Health Incidents Expose 250,000 Patient Records in New Jersey and Texas

Executive Summary

Between July and September 2026, approximately 250,000 individuals were impacted by data breaches at healthcare organizations in New Jersey and Texas, specifically Clover Health and AngMar Management Services. According to the U.S. Department of Health & Human Services (HHS) breach portal and corroborating news sources, these incidents involved unauthorized access to network servers and email systems, resulting in the compromise of protected health information (PHI) and personally identifiable information (PII). The breach at AngMar Management Services is attributed to the Interlock ransomware group, which exfiltrated a significant volume of sensitive data and deployed ransomware. The Clover Health incident was the result of social engineering attacks that compromised employee credentials, with no evidence of ransomware deployment. Both incidents underscore the ongoing targeting of the healthcare sector by threat actors seeking to exploit sensitive patient data for extortion and financial gain. The breaches were officially reported to HHS in mid-September 2026, with public disclosure following in early October 2026.

Technical Information

The data breaches at AngMar Management Services and Clover Health represent significant security incidents within the healthcare sector, characterized by sophisticated attack vectors and substantial data exposure.

For AngMar Management Services, the breach was classified as a "Hacking/IT Incident" affecting network servers, with the presence of a business associate. The attack is attributed to the Interlock ransomware group, a known Ransomware-as-a-Service (RaaS) operation active since at least 2025. While the specific initial access vector is not detailed in public sources, Interlock is known for exploiting exposed Remote Desktop Protocol (RDP) services, phishing campaigns, and credential theft. After gaining access, the attackers exfiltrated approximately 700–710 GB of sensitive data, including PHI such as names, addresses, dates of birth, Social Security numbers, patient IDs, medical record numbers, insurance details, diagnoses, provider names, prescription information, and medical histories. The attackers subsequently deployed ransomware and listed AngMar on their dark web leak site, employing double extortion tactics to pressure the organization into paying a ransom. The technical confidence in attributing this attack to Interlock is high, based on leak site evidence and public claims.

The Clover Health breach, also classified as a "Hacking/IT Incident," involved unauthorized access to network servers and other systems. Attackers gained access to three non-managerial employee accounts through social engineering techniques, as confirmed by the company’s SEC 8-K filing and news reports. These compromised accounts were used for member scheduling and sales, not for financial or claims systems. There is no evidence of ransomware deployment or data encryption in this incident, and the breach was contained without attribution to a specific threat group. The compromised data included PHI and PII, with the exact types under ongoing investigation. The technical confidence for specific malware attribution in this case is low, as no malware or ransomware family has been publicly identified.

Both incidents reflect persistent sector-specific targeting of healthcare organizations for PHI/PII theft and extortion. Ransomware groups like Interlock prioritize healthcare due to the high value of medical data and the urgency of restoring operations. Social engineering and credential theft remain primary initial access vectors, especially for organizations with distributed workforces and third-party associates.

The attack methods observed in these incidents align with several MITRE ATT&CK techniques. For AngMar Management Services, likely techniques include Exploit Public-Facing Application (T1190), Valid Accounts (T1078), Command and Scripting Interpreter (T1059), Create Account (T1136), Exploitation for Privilege Escalation (T1068), Indicator Removal on Host (T1070), OS Credential Dumping (T1003), File and Directory Discovery (T1083), Remote Services (T1021), Automated Collection (T1119), Exfiltration Over C2 Channel (T1041), Data Encrypted for Impact (T1486), and Inhibit System Recovery (T1490). For Clover Health, techniques include Phishing (T1566), Valid Accounts (T1078), Automated Collection (T1119), and Exfiltration Over C2 Channel (T1041).

The evidence supporting these findings is derived from the HHS breach portal, public news reports, and sector-specific threat intelligence. Attribution to Interlock for the AngMar breach is supported by high-confidence technical artifacts, while the Clover Health incident is characterized by medium confidence in the use of social engineering and low confidence in actor attribution.

Affected Versions & Timeline

The breaches affected the following organizations and systems:

AngMar Management Services (TX): The breach impacted network servers and involved a business associate. The incident was officially reported to HHS on September 16, 2026, with the attack occurring in July 2026.

Three Oaks Hospice, Incorporated (TX): The breach affected email systems and involved a business associate. The incident was reported on September 17, 2026.

Clover Health (MN): The breach impacted network servers and other systems, with no business associate involved. The incident was reported on September 14, 2026, with the attack occurring in July 2026.

At Home Medical, Inc. (NJ): The breach involved unauthorized access/disclosure via email, with no business associate involved. The incident was reported on September 16, 2026.

The timeline of verified events is as follows: In July 2026, hackers stole patient information from Clover Health and AngMar Management Services. The breaches were officially submitted to HHS between September 14 and 17, 2026. Public reporting and aggregation of the incident occurred on October 5, 2026.

Threat Activity

The threat activity observed in these incidents demonstrates the evolving tactics of cybercriminal groups targeting the healthcare sector. The Interlock ransomware group, responsible for the AngMar Management Services breach, is known for its double extortion model, combining data theft with ransomware deployment. This group has a history of targeting healthcare, manufacturing, and education sectors, leveraging vulnerabilities in public-facing applications, stolen credentials, and phishing campaigns to gain initial access. Once inside the network, Interlock operators conduct lateral movement, escalate privileges, exfiltrate sensitive data, and deploy ransomware to encrypt critical systems. The group then threatens to leak stolen data on dark web forums if ransom demands are not met.

In the case of Clover Health, the attackers employed social engineering techniques to compromise employee credentials. This method is increasingly common among both criminal and advanced persistent threat (APT) groups targeting healthcare organizations. By exploiting human factors, attackers can bypass technical controls and gain access to sensitive systems and data. The lack of ransomware deployment in this incident suggests a focus on data theft rather than operational disruption.

Both incidents highlight the importance of robust security awareness training, multi-factor authentication, and continuous monitoring to detect and respond to credential-based attacks and ransomware threats.

Mitigation & Workarounds

Mitigation strategies for incidents of this nature should be prioritized by severity:

Critical actions include immediately reviewing and updating access controls for all network servers and email systems, enforcing multi-factor authentication (MFA) for all remote and privileged access, and conducting a comprehensive audit of user accounts and permissions. Organizations should also implement network segmentation to limit lateral movement and deploy endpoint detection and response (EDR) solutions to identify and contain malicious activity.

High-priority measures involve enhancing security awareness training to educate staff about phishing and social engineering tactics, regularly patching and updating all systems to address known vulnerabilities, and monitoring for unusual access patterns or data exfiltration attempts. Incident response plans should be tested and updated to ensure rapid containment and recovery in the event of a breach.

Medium-priority actions include reviewing relationships with business associates and third-party vendors to ensure they adhere to the same security standards, conducting regular risk assessments, and ensuring that data backups are encrypted, tested, and stored offline.

Low-priority recommendations involve maintaining up-to-date asset inventories, participating in sector-specific threat intelligence sharing, and reviewing public-facing applications for unnecessary exposure.

All mitigation efforts should be validated through regular security assessments and penetration testing to ensure effectiveness against evolving threats.

Indicators of Compromise

At the time of writing, no public indicators of compromise (IOCs) such as IP addresses, domains, URLs, or malware hashes have been disclosed in the official sources or corroborating news reports related to these incidents. Organizations are advised to monitor for updates from trusted threat intelligence providers and validate any IOCs before enforcement.

References

U.S. Department of Health & Human Services - Office for Civil Rights Breach Portal: https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf

SecurityIT / Show.it (News Aggregator referencing SecurityWeek): https://www.show.it/250000-impacted-by-data-breaches-at-new-jersey-texas-healthcare-firms/

About Rescana

Rescana provides a Third-Party Risk Management (TPRM) platform designed to help organizations identify, assess, and monitor cybersecurity risks across their vendor and partner ecosystem. Our platform enables continuous risk assessment, automated evidence collection, and actionable insights to support compliance and incident response efforts in the healthcare sector and beyond.

We are happy to answer questions at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.