CareCloud begins to notify hundreds of thousands after hackers stole medical records

CareCloud has confirmed that a cyberattack earlier this year resulted in the theft of sensitive medical and billing records for approximately 345,000 patients. The breach occurred over a six-day period in March, affecting data stored on Amazon Web Services.
Why it matters
This incident highlights the ongoing vulnerability of centralized healthcare data storage and the significant privacy risks posed to millions of patients by large-scale cyberattacks.
Hundreds of thousands of people are receiving letters notifying them that their medical records were stolen in a cyberattack at U.S. health tech giant CareCloud earlier this year, as new details about the data breach come to light.
The company has said little about the breach since March, when it first admitted that hackers had raided one of its six stores of patient data . New disclosures seen by TechCrunch offer the clearest picture of the breach so far, including that nearly 350,000 people have been affected so far.
The New Jersey-based CareCloud stores patient records for more than 45,000 providers across the U.S., including doctors’ offices, hospitals, and other medical practices. As such, the company handles a large amount of sensitive medical and billing data on millions of healthcare patients across the country.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in