1 week ago
CareCloud Confirms Massive Breach Affecting 3.75 Million Patients
CareCloud is a company that helps healthcare providers store medical information and handle billing.
Hackers broke into one of its online storage systems in March.
They had access for six days and took information about more than 3.75 million people.
The stolen information included names, addresses, medical records and Social Security numbers.
It also included some passport, driver’s license and financial information.
This kind of information could make identity theft or financial fraud easier.
CareCloud told the government about the incident and later increased the number of people affected.
The company has not publicly explained who carried out the attack or whether it paid a ransom.
CareCloud reported that more than 3.75 million people were affected by a cyberattack.
Hackers accessed patient information in a CareCloud cloud environment for six days in March.
Stolen data included names, addresses, Social Security numbers, medical records, identification details and financial information.
CareCloud revised its reported victim count upward one day after its initial filing with the U.S. Department of Health and Human Services.
The breach is among the largest reported in U.S. healthcare this year, though DentaQuest has reported a larger incident affecting at least 15 million people.
- Who
- CareCloud and more than 3.75 million people whose information was stored in its systems.
- What
- A cyberattack in which hackers accessed and removed patients’ personal, medical, identification and financial information.
- Where
- A CareCloud cloud environment connected to its Amazon Web Services account in the United States.
- When
- The unauthorized access occurred in March; CareCloud disclosed the affected-people count on August 17 and revised it the following day.
- Why
- The articles do not identify the attackers’ motive; the stolen data could be used for identity theft or financial fraud.
Key facts
- Affected individuals
- More than 3.75 million people
- Access period
- Six days in March
- Exposed information
- Names, postal addresses, Social Security numbers and medical records
- Additional data
- Passport and driver’s license numbers, government-issued identification details, banking and other financial information
- Company
- CareCloud, a New Jersey-based provider of electronic medical record and billing services
- Disclosure
- CareCloud filed the affected-person count with the U.S. Department of Health and Human Services on August 17 and revised it the next day
- Comparative scale
- The incident was described as the fifth-largest U.S. healthcare data theft reported so far that year; DentaQuest reported a breach affecting at least 15 million people








