A massive cyberattack on health-tech giant CareCloud has compromised the sensitive medical and financial records of approximately 350,000 individuals. The stolen data includes Social Security numbers, bank details, and medical histories.

Key Takeaways

  • Approximately 345,000 individuals have been affected by the breach.
  • Stolen data includes names, SSNs, government IDs, and bank account details.
  • The breach occurred over a six-day period in March via AWS-hosted storage.
  • CareCloud manages data for over 45,000 healthcare providers across the U.S.

The health-tech giant CareCloud has begun notifying hundreds of thousands of individuals following a significant cyberattack that resulted in the theft of sensitive medical records. New disclosures reveal that the breach has impacted at least 345,000 people across the United States, a number expected to rise as more state authorities receive filings.

Based in New Jersey, CareCloud serves as a critical data backbone for over 45,000 healthcare providers, including hospitals and private medical practices. According to filings with various Attorneys General, hackers gained unauthorized access to one of the company's electronic health record (EHR) data stores between March 10 and March 16. The attackers specifically targeted data hosted on Amazon Web Services (AWS).

Why This Matters

BozokMedia analysis shows that the healthcare sector remains a high-value target for cybercriminals due to the permanent nature of medical and identity data. Unlike credit cards, which can be canceled, Social Security numbers and medical histories cannot be easily changed, making this stolen information extremely dangerous for long-term identity theft and financial fraud.

The breach of healthcare data represents a profound violation of patient privacy and a systemic failure in protecting critical digital infrastructure.

The scope of the stolen information is extensive. Beyond basic contact details, the breached data includes Social Security numbers, passport numbers, driver’s licenses, and even sensitive financial data such as bank account numbers and payment card information. This combination of data provides a 'gold mine' for malicious actors.

Historical Context

This incident is part of a worrying trend of escalating attacks on the healthcare industry. Earlier this year, the breach at TriZetto affected 3.4 million people, and NYC Health + Hospitals suffered a breach involving 1.8 million patients. The recurring nature of these attacks highlights a massive vulnerability in how medical data is stored and guarded in the cloud.

Did You Know?: Medical records are often sold on the dark web for much higher prices than credit card numbers because they contain permanent information that can be used for insurance fraud.

Frequently Asked Questions

1. What should I do if I am affected?
Monitor your bank statements closely, freeze your credit if necessary, and look out for official correspondence from CareCloud regarding identity protection services.

2. How did the hackers get in?
While the exact method is not fully detailed, reports indicate the breach occurred through the company's data storage hosted on Amazon Web Services.