CareCloud Breach: Data of 345,000 Individuals at Risk
Health tech giant CareCloud has disclosed that a cyberattack in March resulted in the leak of sensitive medical and financial data of 345,000 individuals. Details emerged months later through the company's legal filings.
What Happened
U.S.-based health technology company CareCloud has announced a major data breach affecting approximately 345,000 people. According to an official notice filed with the California Attorney General's office, cyberattackers infiltrated the company's cloud-based systems in March 2026, gaining access to patient records and financial information. Although the incident was vaguely acknowledged back in March, clear details about the scope and content of the breach only came to light months later as a result of legal obligations.
New Jersey-based CareCloud provides critical services such as cloud-based electronic health records (EHR), billing, and revenue cycle management to over 45,000 hospitals, clinics, and private practices across the U.S. This means an attack on the company directly impacts the patients of the thousands of healthcare providers it serves. The company's reported revenue of $120.5 million and net income of $10.8 million for fiscal year 2025 illustrates the scale of its operations and the value of the data it holds. The emergence of these details more than four months after the attack has reignited debates about transparency and timely notification in data breaches.
What Data Was Stolen
The nature of the leaked data highlights the severity of the incident. This breach goes far beyond a simple username and password leak. The information obtained by the attackers is a treasure trove for identity theft and health insurance fraud. According to the company's notice, the compromised data includes:
- Personal Identifiable Information (PII): Names, home addresses, and Social Security numbers.
- Official Identification Documents: Government-issued ID numbers, such as passports and driver's licenses.
- Financial Information: Bank account details and payment card numbers.
- Medical Information: A substantial amount of medical and health information, including diagnoses, treatment histories, insurance details, and other sensitive health data.
The theft of these combined datasets poses serious risks for victims. Fraudsters can use this information to create fake identities, drain bank accounts, or file fraudulent claims for medical services in the victim's name. This type of fraud can also lead to the contamination of victims' medical records with incorrect information, potentially complicating their ability to receive proper treatment in the future.
How Did the Attack Happen
According to CareCloud's official statement, attackers gained unauthorized access to one of the company's electronic health record databases hosted on Amazon Web Services (AWS) between March 10 and March 16, 2026—a period of six days. The company states that the attackers "claimed to have exfiltrated data" from databases within that environment. While this phrasing seems to leave some ambiguity as to whether the data was definitively copied, the act of filing legal notifications reinforces the assumption that the data was compromised.
The company has not yet shared technical details about how the attack was carried out. It is unknown how the attackers infiltrated the AWS environment, what vulnerability they exploited, or how they obtained credentials. The notice also states that no unauthorized activity has been detected in CareCloud's systems since March 16, 2026. No cybercrime group has claimed responsibility for the attack so far.
Who Is Affected
Those directly affected by the breach are patients of the more than 45,000 healthcare providers that use CareCloud's services. This includes doctors' offices, clinics, and large hospitals across the country. Although patients may not have provided their data directly to CareCloud, they became indirect victims of this supply-chain attack because their healthcare provider used the company's infrastructure. While the number of affected individuals is currently stated to be around 345,000, it is noted that this figure is still climbing as more state filings are made.
What You Can Do
If you have received services from a healthcare provider that uses CareCloud and you believe you may be affected by this breach, there are several steps you can take:
- Watch for Official Notifications: Keep a close eye on letters, emails, or other official communications from CareCloud or your healthcare provider. Companies often offer free credit monitoring services to affected individuals in these situations.
- Check Your Accounts: Regularly review your bank and credit card statements for any unexpected or suspicious transactions.
- Monitor Your Credit Reports: Consider placing a fraud alert or a credit freeze on your credit reports with the three major credit bureaus (Equifax, Experian, and TransUnion). This makes it harder for someone to open new accounts in your name.
- Review Your Health Insurance Statements: Check the Explanation of Benefits (EOB) documents from your health insurer. Claims for services you did not receive could be a sign of health insurance fraud.
- Be Wary of Phishing Attempts: Cybercriminals may use the stolen personal information to craft targeted phishing emails or phone calls. Do not trust any communication that requests sensitive information or seems suspicious.
What the Company Is Saying
In its notice to the California Attorney General, CareCloud stated, "The investigation determined that, between March 10 and March 16, 2026, an unauthorized third party accessed one of CareCloud’s AWS environments and claimed to have exfiltrated data from databases within that environment." The company also noted that no further suspicious activity has been detected in its systems since March 16 and that the investigation is ongoing.
However, the company's four-month silence since its initial acknowledgment of the incident in March has drawn criticism. This event once again highlights the role of data breach notification laws, particularly strict regulations like those in California, in compelling companies to be transparent and inform victims in a timely manner. Without these legal requirements, it would be uncertain when the public and the victims would have learned these details. This incident, along with other major cyberattacks in the healthcare sector like the breach at Cognizant's TriZetto affecting 3.4 million people and the data theft at billing software provider Craneware, shows just how much of a target the industry has become.
Source
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.