Visualização de leitura

Medical records, SSNs, and bank details exposed in CareCloud data breach

Healthcare technology giant CareCloud has confirmed that a data breach earlier this year impacted more than 3.75 million people, making it one of the largest healthcare data incidents disclosed this year.

The New Jersey-based company, which provides electronic health record (EHR) and practice management services, first flagged the intrusion in an SEC filing back in March, but the true scope only became clear this month when the Department of Health and Human Services (HHS) breach tracker updated the affected total from roughly 345,000 to 3,756,469 individuals.

CareCloud says an unauthorized third party accessed one of its Amazon Web Services (AWS) environments between March 10 and March 16, 2026. The intrusion caused an eight-hour disruption to one of the company’s six EHR environments before systems were restored that same evening. During a forensic investigation, CareCloud determined that the attacker claimed to have exfiltrated data from databases within that environment.

The stolen data reportedly includes both identity and medical information:

  • Full names, postal addresses, and dates of birth
  • Social Security numbers (SSNs) and driver’s license or passport numbers
  • Medical records and health insurance information
  • Bank account and financial details, plus full credit card data (including CVV) for a limited subset of victims

What affected customers should do

Anyone receiving a breach notification letter should take it seriously, given the combination of medical, identity, and financial data involved.

If you think you’ve been affected by a data breach, here are steps you can take to protect yourself:

  • Check the company’s advice. Every breach is different, so check with the company to find out what’s happened and follow any specific advice it offers.
  • Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
  • Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password, but 2FA that relies on a FIDO2 device can’t be phished.
  • Watch out for impersonators. Cybercriminals may contact you posing as the breached company. Check its official website to see if it’s contacting victims, and verify the identity of anyone who contacts you using a different communication channel.
  • Take your time. Phishing attacks often impersonate people or brands you know and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
  • Consider not storing your card details. It’s definitely more convenient to let sites remember your card details, but it increases the risk if a company suffers a breach.
  • Set up identity monitoring. This can alert you if your personal information is found being traded illegally online and help you recover afterward.

What do cybercriminals know about you?

Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.

CareCloud Breach Exposes Medical and Financial Data of 345,000

CareCloud disclosed a breach affecting 345,000 people after hackers stole medical and financial data from its AWS-hosted systems.

TechCrunch reports that CareCloud, the New Jersey-based health tech company that stores patient records for more than 45,000 providers across the US, is finally notifying people impacted by a breach the firm first disclosed back in March. New disclosures put the number affected so far at nearly 350,000, and that number is still climbing as more states get their filings.

CareCloud is a U.S. healthcare technology company that provides cloud-based electronic health records (EHR), medical practice management, revenue cycle management, billing, and AI-powered software for hospitals and medical practices. It employs approximately 3,650 people, and reported $120.5 million in revenue and $10.8 million in GAAP net income for fiscal year 2025.

CareCloud handles the kind of data that makes a breach genuinely dangerous rather than just annoying. Doctors’ offices, hospitals, and medical practices around the country feed patient records into its systems, which means a hit on CareCloud is really a hit on everyone those providers see. The company stayed mostly quiet for four months after its initial admission, and it took a batch of state filings to fill in the actual details.

According to a data breach notice filed with California’s attorney general’s office this week, threat actors had access to one of CareCloud’s electronic health record data stores for at least six days, from March 10 to March 16.

“The investigation determined that, between March 10 and March 16, 2026, an unauthorized third party accessed one of CareCloud’s AWS environments and claimed to have exfiltrated data from databases within that environment.” reads the data breach notice. “There is no evidence of unauthorized activity within CareCloud’s environment since March 16, 2026.”

The notice states that an attacker claimed to have exfiltrated data from databases.” CareCloud hasn’t provided technical details about the security breach.

At this time, nobody has publicly claimed responsibility for the attack. What the filings do confirm is the technical detail TechCrunch had already reported back in March: the attackers broke into data storage that CareCloud hosted on Amazon Web Services.

Compromised info may include names, home addresses, and Social Security numbers, along with government ID numbers like passports and driver’s licenses. Bank account details and payment card numbers were exposed too, on top of a substantial amount of medical and health information, the exact combination identity thieves and health insurance fraudsters both want.

In March, Cognizant’s TriZetto Provider Solutions disclosed a breach affecting 3.4 million people, and just last week, billing software provider Craneware confirmed hackers stole a significant volume of data belonging to its hospital and pharmacy clients.

These incidents demonstrate how healthcare data keeps ending up in the wrong hands, and the public usually finds out well after the fact. If there’s a silver lining here, it’s that California’s disclosure rules are the reason we know any of this at all this soon. Without a state forcing the paperwork, “we’ll notify affected patients eventually” would probably still be the entire update.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

❌