{"id":3491399,"date":"2026-07-30T20:13:12","date_gmt":"2026-07-30T20:13:12","guid":{"rendered":"https:\/\/techingeek.com\/index.php\/2026\/07\/30\/carecloud-starts-to-inform-hundreds-of-thousands-following-the-theft-of-medical-records-by-hackers\/"},"modified":"2026-07-30T20:13:12","modified_gmt":"2026-07-30T20:13:12","slug":"carecloud-starts-to-inform-hundreds-of-thousands-following-the-theft-of-medical-records-by-hackers","status":"publish","type":"post","link":"https:\/\/techingeek.com\/index.php\/2026\/07\/30\/carecloud-starts-to-inform-hundreds-of-thousands-following-the-theft-of-medical-records-by-hackers\/","title":{"rendered":"CareCloud starts to inform hundreds of thousands following the theft of medical records by hackers."},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/techingeek.com\/wp-content\/uploads\/2026\/07\/carecloud-starts-to-inform-hundreds-of-thousands-following-the-theft-of-medical-records-by-hackers.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Countless individuals are being sent letters informing them that their medical records were compromised during a cyber incident at the U.S. health technology leader CareCloud earlier this year, as fresh information about the data breach emerges.<\/p>\n<p class=\"wp-block-paragraph\">The firm has remained silent about the incident since March, when it first acknowledged that cyber criminals had infiltrated one of its six patient data repositories. New revelations reviewed by TechCrunch provide the most comprehensive overview of the breach to date, including that close to 350,000 individuals have been impacted thus far.<\/p>\n<p class=\"wp-block-paragraph\">Based in New Jersey, CareCloud manages patient records for over 45,000 providers across the U.S., encompassing physician offices, hospitals, and various medical practices. Consequently, the company handles a considerable volume of sensitive medical and billing information pertaining to millions of healthcare patients nationwide.<\/p>\n<p class=\"wp-block-paragraph\">As per a data breach notice submitted to California&#8217;s attorney general\u2019s office this week, CareCloud disclosed that hackers had access to one of its electronic health record data stores for a minimum of six days, from March 10 to March 16. The firm reported that a hacker \u201cpurported to have exfiltrated data from databases.\u201d No details were provided on how the hackers validated this claim, but it is common for cybercriminals to present samples of purloined data to victims along with ransom requests to deter online publication.<\/p>\n<p class=\"wp-block-paragraph\">TechCrunch has not been informed of any ransomware or extortion group taking public responsibility for the data breach at CareCloud.<\/p>\n<p class=\"wp-block-paragraph\">The notice provided minimal information about the hack aside from its initial disclosure on March 27 to regulators, but it corroborated TechCrunch\u2019s previous findings that the hackers infiltrated the company\u2019s data storage hosted on Amazon Web Services.<\/p>\n<p class=\"wp-block-paragraph\">TechCrunch has discovered that the data breach impacts at least 345,000 individuals across the U.S., according to reports from several state attorneys general, including those in New Hampshire, Massachusetts, and Texas. TechCrunch has also obtained CareCloud\u2019s report submitted to Maine\u2019s attorney general.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The count of affected individuals is expected to increase as additional notifications are filed with state agencies.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The notifications confirm that CareCloud alerted authorities that the compromised data encompassed individuals\u2019 names, mailing addresses, and Social Security numbers, along with government-issued IDs, such as passports and driver\u2019s licenses. Moreover, the notifications indicate that the stolen data contained financial details, including bank account information and credit card numbers, along with a broad range of medical and health-related information.<\/p>\n<p class=\"wp-block-paragraph\">CareCloud&#8217;s CEO Stephen Snyder did not reply to TechCrunch\u2019s inquiry for a statement or to questions regarding the situation.<\/p>\n<p class=\"wp-block-paragraph\">The cyberattack aimed at CareCloud is the latest in a series of data breaches affecting healthcare providers this year, including an incident involving healthcare revenue tech leader TriZetto that impacted 3.4 million individuals, and a month-long breach at New York\u2019s public health provider NYC Health + Hospitals, where hackers acquired 1.8 million individuals\u2019 health records and numerous employees\u2019 fingerprint scans.<\/p>\n<p class=\"wp-block-paragraph\">Last week, U.K.-based tech company Craneware, which offers accounting and billing software to thousands of U.S. healthcare providers, confirmed that hackers had pilfered a \u201csignificant volume\u201d of data belonging to its clients from their servers, raising alarms about a breach concerning patient data.<\/p>\n<p class=\"wp-block-paragraph\"><em><strong>Are you aware of more details regarding CareCloud\u2019s data breach? Do you have insider knowledge about its security measures while working at CareCloud? Reach out to this reporter via encrypted message at zackwhittaker.1337 on Signal.<\/strong><\/em><\/p>\n<\/div>\n<p><em>Purchasing through links in our articles may earn us a small commission, which does not impact our editorial autonomy.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/techingeek.com\/wp-content\/uploads\/2026\/07\/carecloud-starts-to-inform-hundreds-of-thousands-following-the-theft-of-medical-records-by-hackers.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Countless individuals are being sent letters informing them that their medical records were compromised during a cyber incident at the U.S. health technology leader CareCloud earlier this year, as fresh information about the data breach emerges.<\/p>\n<p class=\"wp-block-paragraph\">The firm has remained silent about the incident since March, when it first acknowledged that cyber criminals had infiltrated one of its six patient data repositories. New revelations reviewed by TechCrunch provide the most comprehensive overview of the breach to date, including that close to 350,000 individuals have been impacted thus far.<\/p>\n<p class=\"wp-block-paragraph\">Based in New Jersey, CareCloud manages patient records for over 45,000 providers across the U.S., encompassing physician offices, hospitals, and various medical practices. Consequently, the company handles a considerable volume of sensitive medical and billing information pertaining to millions of healthcare patients nationwide.<\/p>\n<p class=\"wp-block-paragraph\">As per a data breach notice submitted to California&#8217;s attorney general\u2019s office this week, CareCloud disclosed that hackers had access to one of its electronic health record data stores for a minimum of six days, from March 10 to March 16. The firm reported that a hacker \u201cpurported to have exfiltrated data from databases.\u201d No details were provided on how the hackers validated this claim, but it is common for cybercriminals to present samples of purloined data to victims along with ransom requests to deter online publication.<\/p>\n<p class=\"wp-block-paragraph\">TechCrunch has not been informed of any ransomware or extortion group taking public responsibility for the data breach at CareCloud.<\/p>\n<p class=\"wp-block-paragraph\">The notice provided minimal information about the hack aside from its initial disclosure on March 27 to regulators, but it corroborated TechCrunch\u2019s previous findings that the hackers infiltrated the company\u2019s data storage hosted on Amazon Web Services.<\/p>\n<p class=\"wp-block-paragraph\">TechCrunch has discovered that the data breach impacts at least 345,000 individuals across the U.S., according to reports from several state attorneys general, including those in New Hampshire, Massachusetts, and Texas. TechCrunch has also obtained CareCloud\u2019s report submitted to Maine\u2019s attorney general.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The count of affected individuals is expected to increase as additional notifications are filed with state agencies.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The notifications confirm that CareCloud alerted authorities that the compromised data encompassed individuals\u2019 names, mailing addresses, and Social Security numbers, along with government-issued IDs, such as passports and driver\u2019s licenses. Moreover, the notifications indicate that the stolen data contained financial details, including bank account information and credit card numbers, along with a broad range of medical and health-related information.<\/p>\n<p class=\"wp-block-paragraph\">CareCloud&#8217;s CEO Stephen Snyder did not reply to TechCrunch\u2019s inquiry for a statement or to questions regarding the situation.<\/p>\n<p class=\"wp-block-paragraph\">The cyberattack aimed at CareCloud is the latest in a series of data breaches affecting healthcare providers this year, including an incident involving healthcare revenue tech leader TriZetto that impacted 3.4 million individuals, and a month-long breach at New York\u2019s public health provider NYC Health + Hospitals, where hackers acquired 1.8 million individuals\u2019 health records and numerous employees\u2019 fingerprint scans.<\/p>\n<p class=\"wp-block-paragraph\">Last week, U.K.-based tech company Craneware, which offers accounting and billing software to thousands of U.S. healthcare providers, confirmed that hackers had pilfered a \u201csignificant volume\u201d of data belonging to its clients from their servers, raising alarms about a breach concerning patient data.<\/p>\n<p class=\"wp-block-paragraph\"><em><strong>Are you aware of more details regarding CareCloud\u2019s data breach? Do you have insider knowledge about its security measures while working at CareCloud? Reach out to this reporter via encrypted message at zackwhittaker.1337 on Signal.<\/strong><\/em><\/p>\n<\/div>\n<p><em>Purchasing through links in our articles may earn us a small commission, which does not impact our editorial autonomy.<\/em><\/p>\n","protected":false},"author":2,"featured_media":3491400,"comment_status":"open","ping_status":"closed","sticky":false,"template":"Default","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3491399","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/posts\/3491399"}],"collection":[{"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/comments?post=3491399"}],"version-history":[{"count":0,"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/posts\/3491399\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/media\/3491400"}],"wp:attachment":[{"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/media?parent=3491399"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/categories?post=3491399"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techingeek.com\/index.php\/wp-json\/wp\/v2\/tags?post=3491399"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}