CareCloud starts to inform hundreds of thousands following the theft of medical records by hackers.

CareCloud starts to inform hundreds of thousands following the theft of medical records by hackers.

Countless individuals are being sent letters informing them that their medical records were compromised during a cyber incident at the U.S. health technology leader CareCloud earlier this year, as fresh information about the data breach emerges.

The firm has remained silent about the incident since March, when it first acknowledged that cyber criminals had infiltrated one of its six patient data repositories. New revelations reviewed by TechCrunch provide the most comprehensive overview of the breach to date, including that close to 350,000 individuals have been impacted thus far.

Based in New Jersey, CareCloud manages patient records for over 45,000 providers across the U.S., encompassing physician offices, hospitals, and various medical practices. Consequently, the company handles a considerable volume of sensitive medical and billing information pertaining to millions of healthcare patients nationwide.

As per a data breach notice submitted to California’s attorney general’s office this week, CareCloud disclosed that hackers had access to one of its electronic health record data stores for a minimum of six days, from March 10 to March 16. The firm reported that a hacker “purported to have exfiltrated data from databases.” No details were provided on how the hackers validated this claim, but it is common for cybercriminals to present samples of purloined data to victims along with ransom requests to deter online publication.

TechCrunch has not been informed of any ransomware or extortion group taking public responsibility for the data breach at CareCloud.

The notice provided minimal information about the hack aside from its initial disclosure on March 27 to regulators, but it corroborated TechCrunch’s previous findings that the hackers infiltrated the company’s data storage hosted on Amazon Web Services.

TechCrunch has discovered that the data breach impacts at least 345,000 individuals across the U.S., according to reports from several state attorneys general, including those in New Hampshire, Massachusetts, and Texas. TechCrunch has also obtained CareCloud’s report submitted to Maine’s attorney general. 

The count of affected individuals is expected to increase as additional notifications are filed with state agencies. 

The notifications confirm that CareCloud alerted authorities that the compromised data encompassed individuals’ names, mailing addresses, and Social Security numbers, along with government-issued IDs, such as passports and driver’s licenses. Moreover, the notifications indicate that the stolen data contained financial details, including bank account information and credit card numbers, along with a broad range of medical and health-related information.

CareCloud’s CEO Stephen Snyder did not reply to TechCrunch’s inquiry for a statement or to questions regarding the situation.

The cyberattack aimed at CareCloud is the latest in a series of data breaches affecting healthcare providers this year, including an incident involving healthcare revenue tech leader TriZetto that impacted 3.4 million individuals, and a month-long breach at New York’s public health provider NYC Health + Hospitals, where hackers acquired 1.8 million individuals’ health records and numerous employees’ fingerprint scans.

Last week, U.K.-based tech company Craneware, which offers accounting and billing software to thousands of U.S. healthcare providers, confirmed that hackers had pilfered a “significant volume” of data belonging to its clients from their servers, raising alarms about a breach concerning patient data.

Are you aware of more details regarding CareCloud’s data breach? Do you have insider knowledge about its security measures while working at CareCloud? Reach out to this reporter via encrypted message at zackwhittaker.1337 on Signal.

Purchasing through links in our articles may earn us a small commission, which does not impact our editorial autonomy.