CareCloud Breach Exposes Sensitive Data of 3.7 Million Patients
Electronic health record provider CareCloud has disclosed a data breach affecting 3,756,469 individuals, with sensitive patient information exfiltrated over an eight-day period.

Electronic health record provider CareCloud has reported a significant data breach that impacted approximately 3.7 million individuals, compromising sensitive personal and medical information. The incident, which occurred in March, saw a hacker gain unauthorized access to one of the company's AWS environments for an extended period, leading to the exfiltration of a wide range of data.
According to breach notification letters filed with state regulators, the unauthorized access lasted from March 10 to March 16. During this time, the attacker was able to steal a variety of sensitive information. This included personal details, Social Security numbers, identification numbers, credit and debit card information, as well as medical histories and insurance data.
CareCloud, a major provider of technology and software solutions to hospitals and medical practices, initially reported the incident to law enforcement. However, by March 24, the company's officials decided to inform the Securities Exchange Commission (SEC) due to the sensitive nature of the compromised data and the potential ramifications of the breach.
The scale of the breach is substantial, with specific numbers of affected individuals reported in several states. Texas reported over 270,000 affected residents, South Carolina had nearly 23,000, and Oregon identified close to 58,000 individuals whose data was compromised. New Hampshire, Massachusetts, and California did not disclose the exact number of their residents impacted.
CareCloud serves over 45,000 providers, offering essential services such as electronic health record (EHR) systems and digital revenue cycle management products. The company's financial standing, with reported revenues of $120.5 million in the last fiscal year, underscores its significant role in the healthcare technology sector.
As of the reporting, no specific hacking group has claimed responsibility for the attack. However, the healthcare sector has been a persistent target for cybercriminals. In the past year, numerous large EHR companies and healthcare providers have fallen victim to attacks, including one incident affecting over 2,000 hospitals in the United States.
The breach highlights ongoing vulnerabilities within the healthcare IT infrastructure, where vast amounts of sensitive patient data are stored and processed. The extended access period and the breadth of data exfiltrated underscore the sophisticated methods employed by threat actors and the critical need for robust security measures in healthcare systems.
This incident serves as a stark reminder of the persistent threats facing the healthcare industry and the potential consequences for both providers and patients when sensitive health information is compromised. Organizations like CareCloud are under increasing pressure to fortify their defenses against evolving cyber threats.