Skip to content
Breaking:

CareCloud Breach Exposes Medical and Financial Data of at Least 345,000 People

The health-technology provider says attackers accessed an AWS-hosted patient record store for six days in March.

By The Company Wire2 min read
Share
CareCloud — CareCloud Breach Exposes Medical and Financial Data of at Least 345,000 People
CareCloud — CareCloud Breach Exposes Medical and Financial Data of at Least 345,000 People. Flashlight beam shining on medical records as someone is up to no good..

CareCloud has begun notifying at least 345,000 people that hackers stole sensitive information from one of the company's electronic health-record systems. State filings indicate the number may rise as additional healthcare providers and jurisdictions complete their disclosures.

The company said attackers had access to the data store from March 10 through March 16 and claimed to have removed information from its databases. CareCloud first disclosed the incident on March 27 but released few details. Later notices confirmed that the affected environment was hosted on Amazon Web Services.

Stolen records may include names, addresses, Social Security numbers, passport or driver's-license information, bank account details, payment-card numbers and medical data. That combination creates long-term risk because health and identity information cannot be changed as easily as a password.

CareCloud provides software and stores records for more than 45,000 medical providers across the United States. A compromise at a central technology vendor can therefore expose patients who may never recognize the company's name. The incident illustrates how healthcare consolidation moves risk into shared infrastructure.

Medical identity theft can remain useful to criminals for years. Insurers and providers should watch for false claims, altered contact information and attempts to obtain treatment under another person's identity. CareCloud's response should therefore extend beyond consumer credit files and include practical support for correcting medical records that may be contaminated after misuse.

The notification will test whether CareCloud can provide more than a standard credit-monitoring offer. Medical records include diagnoses, identifiers and insurance information that can be exploited even when a credit file is frozen. Affected people need clear dates, the types of data involved and a contact able to correct fraudulent entries. Providers using CareCloud should review their own access logs and continuity plans. Healthcare vendors hold information across many organizations, so one incident can become a sector-wide risk if customers assume the platform alone will detect every downstream misuse.

The company has not publicly identified the attacker or said whether it received a ransom demand. It should provide clearer information about the entry point, containment, affected systems and support available to patients. Free credit monitoring is useful, but healthcare providers also need assurance that the same storage architecture cannot be accessed through the original weakness.

Sources

  1. Techcrunch report
  2. Oag report
  3. Sec report

Company: CareCloud

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.