
carecloud breach Hundreds of thousands of people are now being told that their medical records and other personal data were stolen in a cyberattack on U.S. health tech company CareCloud earlier this year, as new disclosures provide the clearest picture yet of the breach.
carecloud breach
CareCloud begins sending breach notices
CareCloud, a New Jersey-based company that provides technology and records management services to more than 45,000 healthcare providers across the United States, first acknowledged the incident in March. Since then, the company has said little publicly about what happened. New filings now indicate that the scope is far larger than initially understood, with nearly 350,000 people affected so far.
According to a breach notice filed this week with California’s attorney general, hackers accessed one of CareCloud’s electronic health record data stores for at least six days, from March 10 through March 16. The company said the attacker “claimed to have exfiltrated data from databases.” CareCloud did not explain how the claim was communicated, though such claims are often accompanied by samples of stolen material and ransom demands intended to stop publication of the data.
TechCrunch said it is unaware of any ransomware or extortion group publicly taking credit for the attack.
What the disclosures say was stolen
The newly filed notices confirm that the incident involved data stored in CareCloud’s environment on Amazon Web Services, matching TechCrunch’s earlier reporting. The filings also show that the information taken was extensive and sensitive.
According to the disclosures, the stolen data included:
- Names
- Postal addresses
- Social Security numbers
- Government-issued identification numbers, including passports and driver’s licenses
- Financial information, including bank account information and payment card numbers
- Medical and health-related information
Because CareCloud handles data for providers across the country, the breach potentially exposes a wide range of personal and clinical records tied to patients who may never have directly interacted with the company. CareCloud stores patient records for doctors’ offices, hospitals, and other medical practices, which means the company serves as a critical back-end vendor in the healthcare ecosystem.
At least 345,000 people affected, and the total may grow
TechCrunch learned that the breach affects at least 345,000 people in the United States, based on listings filed with attorneys general in New Hampshire, Massachusetts, and Texas. The outlet also obtained CareCloud’s disclosure to Maine’s attorney general. Because state breach notifications are filed separately and on different timelines, the final total may increase as additional notices are submitted.
The breach notice in California did not add much beyond what was already disclosed on March 27, when CareCloud first informed regulators that an incident had occurred. But the combined filings help establish a more complete timeline and the type of data involved.
CareCloud said the hackers had access to one of its six stores of patient data. That detail is significant because it suggests the compromise was limited to a specific environment rather than every system the company operates. Even so, the exposed material appears to include a broad mix of medical, billing, identity, and financial information.
Why the incident matters for healthcare
Healthcare breaches are especially sensitive because stolen records can be used for identity theft, insurance fraud, medical fraud, and targeted phishing. Unlike a compromised password, medical data cannot be easily changed. Social Security numbers, government IDs, and payment details are also highly valuable to criminals.
CareCloud’s role in the sector makes the incident particularly consequential. The company supports more than 45,000 providers, which means it sits behind a large volume of patient data across the country. When a vendor of this scale is breached, the impact can extend well beyond one health system or one clinic.
The company’s breach also fits into a broader pattern of cyberattacks against healthcare organizations this year. The industry has been hit by several notable incidents involving millions of people, highlighting the continuing pressure on providers and their technology vendors to secure sensitive systems.
Part of a wider wave of healthcare breaches
CareCloud is the latest healthcare-related company to disclose a major intrusion. Earlier this year, healthcare revenue technology giant TriZetto said a breach affected 3.4 million people. In another incident, New York’s public health provider NYC Health + Hospitals said a month-long breach led hackers to steal the health data of 1.8 million people, along with thousands of employees’ fingerprint scans.
Last week, U.K.-based tech provider Craneware, which supplies accounting and billing software to thousands of U.S. healthcare providers, confirmed that hackers stole a “significant volume” of customer data from its servers. That disclosure added to concerns that patient-related data may be exposed through third-party service providers even when the providers themselves are not the direct target.
The CareCloud case shows how health tech vendors remain attractive targets because they centralize large volumes of sensitive data. A single intrusion into one cloud-hosted store can create risk across many practices and many states at once.
Little public response from the company
CareCloud chief executive Stephen Snyder did not respond to TechCrunch’s request for comment or to questions about the incident. The company has also been relatively quiet publicly since its initial March disclosure to regulators.
That limited communication leaves affected individuals and providers with only partial answers about how the intrusion happened, how long the attackers remained in the environment, and what steps were taken to contain the breach. The filings do confirm, however, that the company has begun notifying victims as required by law.
For patients, the practical consequences may unfold over time. Breach notices typically arrive weeks or months after the original intrusion, and the risks associated with the theft can persist long after the incident is contained. People whose Social Security numbers, health information, and financial records were exposed may need to monitor accounts, medical statements, and credit activity carefully.
What to watch next
The total number of affected people may continue to rise as more state-level breach notices are filed. Because healthcare companies often notify regulators in multiple states, the public picture of the incident can change as each filing becomes available.
For now, the disclosures suggest that the CareCloud attack was not a minor security event but a major compromise of sensitive records affecting hundreds of thousands of people. The company’s customers — and the patients whose data sits in its systems — will likely be looking for more detailed explanations of what happened and what safeguards were in place.
Explore more: Blog Our Services Contact Us
Source: Original report
Was this helpful?
Last Modified: July 31, 2026 at 6:37 pm
2 views
