Tech

CareCloud data breach: what happened to 350,000 patients' medical records

TechCrunch2 h ago
A security-focused data server room
A security-focused data server roomPhoto: Brett Sayles / Pexels

New Jersey-based health technology company CareCloud has confirmed that hackers accessed one of its electronic medical record databases for at least six days — between 10 and 16 March 2026 — according to a notification the company filed with the California Attorney General's office.

CareCloud maintains patient databases for more than 45,000 doctor's offices, hospitals and other medical institutions across the United States, making it one of the country's largest health technology infrastructure providers. Its systems hold highly confidential medical and billing data for millions of patients.

Company representatives said unidentified attackers claimed to have either deleted or copied data from the databases — a statement that leaves some ambiguity about exactly what the attackers did once inside, a common uncertainty in breach disclosures of this kind.

Although the incident occurred in March, notification letters to affected individuals only began going out in July — a timeline that reflects the months typically spent scoping an investigation and compiling a complete list of affected records in healthcare data breaches.

Roughly 350,000 people in total are estimated to have been affected. Healthcare data breaches are considered especially serious because the stolen information often includes highly sensitive, durable data such as Social Security numbers, diagnosis codes, prescription history and insurance details — information that, unlike a credit card number, cannot easily be changed.

The attackers were found to have breached CareCloud's data storage infrastructure hosted on Amazon Web Services. This reflects a common pattern in healthcare-sector attacks, where the cloud infrastructure of major technology providers itself is not compromised; rather, attackers exploit vulnerabilities within a customer account.

No known hacker group or ransomware gang has claimed responsibility for the attack so far, distinguishing it from some high-profile ransomware incidents in which responsibility is publicly announced as a matter of course.

This is not an isolated incident for CareCloud. In late March, the company had already disclosed a separate data access event connected to the same breach, indicating the timeline and full scope of the incident have come into focus gradually over months of investigation.

Cybersecurity experts note that healthcare data infrastructure providers have become centralised enough that a single breach can simultaneously affect thousands of healthcare organisations and millions of patients. That concentration offers attackers a large data payoff from a single target, while also significantly widening the blast radius of any one vulnerability on the defensive side.

Affected individuals are being offered identity theft monitoring services, and security experts recommend that anyone who receives a notification letter closely monitor their credit reports and remain alert to medical identity theft, since stolen medical information can also be misused for fraudulent insurance claims or prescription fraud.

This article is an AI-curated summary based on TechCrunch. The illustration is a stock photo by Brett Sayles from Pexels.

Read next

A quantum computer chip inside a cryostat
Tech

Quantum advantage: how do we know a quantum computer's results are correct?

Teams including IBM, the University of Chicago, Algorithmiq, Qedma and RIKEN published three separate papers on the same day, 30 July, each claiming to perform calculations beyond the reach of classical computers — this time with built-in verification methods that can confirm the results are accurate. The work tackles the question that has long undermined 'quantum advantage' claims: if you can't check the answer classically, how do you know it's right?

Ars Technica2 h ago