US health tech giant CareCloud has begun notifying at least 345,000 patients across the United States that their highly sensitive medical and financial records were stolen during a six-day cyberattack in March.
The New Jersey-based healthcare technology firm had remained largely silent about the security incident since March, when it initially acknowledged that unauthorised actors had accessed one of its six patient data repositories. However, newly surfaced regulatory disclosures now provide a clearer picture of the breach, confirming that hundreds of thousands of individuals have been affected.
Inside the Six-Day Data Exfiltration
CareCloud manages sensitive medical and billing data for millions of patients, serving over 45,000 healthcare providers across the US, including hospitals, clinics, and private practices. This extensive network makes the company a high-value target for cybercriminals seeking lucrative medical records.
According to a data breach notice filed with the California Attorney General’s office, the intruders maintained access to one of CareCloud’s electronic health record databases for nearly a week, specifically between 10 March and 16 March. The company disclosed that an attacker claimed to have exfiltrated data directly from these databases. While CareCloud did not specify how this claim was communicated, cybercriminals frequently present stolen data samples to victims alongside ransom demands to coerce payment before publishing the information online.
At present, no known ransomware or extortion group has publicly claimed responsibility for the cyberattack on CareCloud.
Hackers Targeted AWS Cloud Storage
The regulatory filing builds upon CareCloud’s initial March 27 disclosure to federal regulators, confirming that the breach involved unauthorised access to the company’s Amazon Web Services (AWS) cloud storage infrastructure.
Data breach notifications submitted to attorneys general in states such as New Hampshire, Massachusetts, Texas, and Maine confirm that at least 345,000 people have been impacted so far.
var playerInstance_jwplayer_6a7a05747bb49 = jwplayer( “jwplayer_6a7a05747bb49” );
playerInstance_jwplayer_6a7a05747bb49.setup({
playlist: “https://cdn.jwplayer.com/v2/media/lv0GaEwB”,
});
The total number of affected individuals is expected to rise as more regional authorities receive formal notifications from the company.
What Sensitive Information Was Compromised?
The compromised datasets contain highly sensitive personal and clinical details. According to the state notifications, the stolen information includes full names, postal addresses, Social Security numbers, and government-issued identification, including passports and driver’s licences. Furthermore, the breach exposed financial details, including bank account information and payment card numbers, alongside a wealth of medical and health-related records.
CareCloud Chief Executive Stephen Snyder has not responded to requests for comment regarding the security failure or the company’s ongoing response efforts.
A Growing Wave of Healthcare Cyberattacks
The breach at CareCloud is part of a broader trend of aggressive cyber campaigns targeting the healthcare sector. Earlier this year, healthcare revenue technology firm TriZetto suffered a breach affecting 3.4 million individuals, while a month-long cyberattack at NYC Health + Hospitals resulted in the theft of 1.8 million patient records and thousands of employee fingerprint scans.
Furthermore, UK-based software provider Craneware, which services thousands of US healthcare providers with billing and accounting systems, recently confirmed that attackers exfiltrated a significant volume of customer data, highlighting the systemic vulnerabilities facing the global healthcare supply chain.
