CareCloud Breach Exposure Hits 350,000 as Patient Data Stolen from AWS Servers
Recent filings with state attorneys general reveal that a March cyberattack against CareCloud compromised the sensitive personal and financial data of nearly 350,000 individuals. The New Jersey-based health tech provider confirms hackers held access to internal databases for six days.
Key takeaways
- Hackers maintained access to CareCloud's electronic health record databases for six days in March 2024.
- Filings with state attorneys general confirm at least 345,000 individuals are currently impacted by the breach.
- Compromised data includes Social Security numbers, passport details, bank accounts, and sensitive medical histories.
- The breach targeted the company's data storage hosted on Amazon Web Services (AWS).
- CareCloud serves over 45,000 U.S. healthcare providers, making the breach's reach nationwide.
Six-Day Intrusion Leads to Massive Data Exfiltration
New Jersey-based healthcare technology firm CareCloud has begun notifying approximately 345,000 individuals that their medical and personal records were compromised during a cyberattack earlier this year. According to regulatory filings submitted to the California attorney general’s office, unauthorized actors maintained access to an electronic health record data store between March 10 and March 16. During this window, the attacker claimed to have successfully exfiltrated information from the company's databases.
While the firm initially acknowledged the breach in late March, recent disclosures provide the first comprehensive look at the scale of the incident. The hackers targeted data storage hosted on Amazon Web Services (AWS), a detail confirmed by several state filings including those in New Hampshire, Massachusetts, and Texas. While hackers often provide samples of stolen data to back up extortion demands, no specific ransomware group has publicly claimed responsibility for the CareCloud intrusion.
Sensitive Records and Financial Information Comprised
The scope of the stolen data extends far beyond basic contact information. Notices sent to state authorities in Maine and other jurisdictions indicate that the following data points were compromised:
- Full names and residential addresses.
- Social Security numbers and government-issued IDs, including passports and driver’s licenses.
- Financial data such as bank account details and payment card numbers.
- Comprehensive medical records and health-related information.
CareCloud manages records for over 45,000 healthcare providers across the United States. With its vast repository of billing and clinical data, the company serves as a high-value target for digital intruders.
The Rising Toll of Healthcare Sector Vulnerabilities
This incident follows a troubling pattern of large-scale data thefts targeting the medical industry. Earlier this year, NYC Health + Hospitals reported a month-long breach affecting 1.8 million people, while revenue technology firm TriZetto saw 3.4 million records exposed. Most recently, U.K.-based Craneware confirmed a significant volume of customer data was stolen from its servers, which service thousands of American medical facilities. CareCloud CEO Stephen Snyder has not commented on the security failure or the specifics of the company's defensive protocols.
Source: Tech Crunch
Related stories

Patnaik Decries Saffron Rebranding of Indian Hockey as Erosion of Sporting History

Post-Protest Harassment Persists Despite Government Pledges to Drop Firs
Apple Defies Component Scarcity as iPhone and Mac Revenue Surges

