ThreatPaper
Weak Evidence

250,000 people affected across the two healthcare breaches

Assessment

SecurityWeek headlined '250,000 Impacted' (body: 'more than 250,000 people'), and OODA Loop and Rescana used 'approximately 250,000 individuals combined'. The figure is a sum of two unrelated breaches that each outlet reports separately: Clover Health's 138,677 and AngMar's 126,196, per their HHS OCR filings, total 264,873. The round 250,000 understates the filed total by nearly 15,000 people and, by presenting a sum as a single incident count, blends a social-engineering breach with no ransomware claim and a confirmed ransomware attack. The evidence for '250,000' is weak in the sense that it is a rounded compression, not a figure any filing states.

Where this claim appeared

SecurityWeek · 2026-10-05

https://www.securityweek.com/250000-impacted-by-data-breaches-at-new-jersey-texas-healthcare-firms/

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

Clover Health and AngMar breaches: 264,873 affected across two US healthcare firms

Think this assessment is wrong? Report an error.