top of page
OutSystems-business-transformation-with-gen-ai-ad-300x600.jpg
OutSystems-business-transformation-with-gen-ai-ad-728x90.jpg
TechNewsHub_Strip_v1.jpg

LATEST NEWS

CareCloud notifies 345,000 patients months after breach exposed sensitive health and financial records

  • Marijan Hassan - Tech Journalist
  • 16 hours ago
  • 2 min read

Healthcare technology provider CareCloud has begun notifying hundreds of thousands of individuals that their highly sensitive personal, medical, and financial records were compromised during a cyberattack on its electronic health record (EHR) infrastructure. State regulatory filings reveal that at least 345,000 patients across the United States were impacted by the security breach, four months after the company first reported an operational disruption to federal regulators.



Unauthorized Access to Cloud-Hosted Medical Systems

The security incident occurred between March 10 and March 16, when unauthorized third parties breached one of CareCloud’s six electronic health record environments hosted on Amazon Web Services. The intrusion caused an eight-hour service outage before IT teams successfully restored network functionality and locked out the attackers.


While CareCloud initially disclosed the disruption in a late-March regulatory filing with the U.S. Securities and Exchange Commission, forensic investigations conducted by Big Four cybersecurity advisory teams later confirmed that threat actors had accessed and exfiltrated sensitive databases within the compromised environment. CareCloud provides EHR, revenue cycle management, and practice management software to more than 45,000 healthcare providers nationwide.


Extensive Exposure of High-Risk Identity Data

The data exfiltrated during the breach contains a dangerous mix of personal, financial, and clinical identifiers. According to victim notification letters, compromised information includes:


  • Government Identification: Social Security numbers, driver’s license details, and passport numbers.

  • Financial Details: Bank account credentials and payment card numbers.

  • Personal & Medical Records: Full names, postal addresses, and detailed health and treatment information.


Cybersecurity experts warn that the exposure of combined medical histories, financial records, and government identification creates an exceptionally high risk of targeted phishing attacks, identity theft, and fraudulent medical billing.


Mitigation and future outlook

CareCloud confirmed it has implemented additional firewall protections, enhanced database access controls, and engaged external incident-response teams to audit its remaining cloud environments. The company is offering affected individuals complimentary credit monitoring and identity restoration services while advising patients to closely review their Explanation of Benefits (EOB) statements for unauthorized medical claims.


The CareCloud breach is the latest in a series of cyberattacks targeting healthcare organizations, which store vast amounts of valuable personal, financial, and medical information. As investigations continue, the total number of affected individuals could increase as additional disclosures are filed with state regulators.

wasabi.png
Gamma_300x600.jpg
paypal.png
bottom of page