CareCloud Cyberattack Exposes Patient Records and Personal Information for Hundreds of Thousands
New Jersey-based health technology provider CareCloud has begun issuing notification letters to hundreds of thousands of people following a cyberattack that exposed sensitive patient records. Disclosures filed with state authorities show that at least 345,000 people across the United States have been impacted, with the overall number expected to increase as additional filings are submitted.
What Happened
CareCloud, which maintains health records for more than 45,000 healthcare providers across the United States, disclosed that unauthorized individuals accessed one of its six electronic health record stores hosted on Amazon Web Services. According to regulatory filings with California’s attorney general office, hackers had access to the database between March 10 and March 16. The intruder claimed to have exfiltrated data from the system. CareCloud first submitted a disclosure regarding the breach to regulators on March 27.
Key Highlights
- Impacted Population: Regulatory disclosures filed with attorneys general in California, Maine, Massachusetts, New Hampshire, and Texas confirm at least 345,000 individuals are affected.
- Exfiltrated Personal Data: Compromised records contain names, home addresses, Social Security numbers, driver’s licenses, and passport numbers.
- Financial and Medical Records Stolen: The breach involved financial details, such as bank accounts and payment card information, alongside health and medical data.
- Systems Affected: The intrusion targeted one of CareCloud’s six electronic health record storage systems hosted on Amazon Web Services.
- Executive Response: CareCloud Chief Executive Stephen Snyder did not respond to requests for comment regarding the incident.
Why This Matters
CareCloud manages extensive billing and medical data for doctors’ offices, hospitals, and medical practices across the country. The exposure of sensitive medical information alongside government identification and financial details presents notable privacy risks for patients. This incident is part of a broader series of cyber breaches affecting healthcare tech and service providers this year, including incidents at TriZetto, NYC Health + Hospitals, and Craneware.
What to Watch Next
CareCloud is currently notifying affected individuals via mail. Additional state regulatory disclosures are expected to be filed, which will provide a updated count of the total number of individuals whose records were compromised.
Frequently Asked Questions
When did the CareCloud data breach occur?
Hackers accessed CareCloud’s Amazon Web Services database between March 10 and March 16, following an initial disclosure to regulators on March 27.
What type of information was compromised in the breach?
Stolen data included patient names, postal addresses, Social Security numbers, driver’s license numbers, passport numbers, payment card details, bank account details, and medical records.
How many people are confirmed to be affected?
Filings with several state attorneys general show at least 345,000 affected individuals, though the final count is expected to rise as further reports are processed.
Source: Based on TechCrunch reporting and state regulatory filings.
