CareCloud has confirmed to federal regulators that hackers stole personal and medical records belonging to more than 3.75 million patients, making it the fifth-largest healthcare data theft so far this year. The March breach, disclosed in an HHS filing, involved attackers exfiltrating data from CareCloud's AWS account over a six-day period. Stolen information includes names, addresses, Social Security numbers, medical records, government IDs, and banking details. CareCloud's CEO Stephen Snyder has not responded to requests for comment. The incident follows other major healthcare breaches this year at TriZetto, Craneware, and DentaQuest.
Questions this post answers
How many people were affected by the CareCloud data breach?
More than 3.75 million people had their personal and medical records stolen in the CareCloud data breach, making it the fifth-largest healthcare data theft reported so far this year. The number was revised upward from an earlier figure after CareCloud's update to federal regulators. Stolen data includes names, addresses, Social Security numbers, medical records, government IDs, and banking information. Track how healthcare data breaches unfold and scale by following security incident coverage on daily.dev.
How did hackers breach CareCloud's systems?
Hackers exfiltrated patient data from CareCloud's Amazon Web Services account over a six-day period in March. CareCloud disclosed that attackers accessed medical data stored in one of its cloud storage environments, later confirming the data was pulled directly from its AWS environment. The company has not detailed the specific vulnerability or attack method exploited. Developers securing cloud storage environments can follow breach postmortems like this on daily.dev.