CareCloud begins to notify hundreds of thousands after hackers stole medical records
Hundreds of thousands of people are receiving letters notifying them that their medical records were stolen in a cyberattack at U.S. health tech giant CareCloud earlier this year, as new details about the data breach come to light.
The company has said little about the breach since March, when it first admitted that hackers had raided one of its six stores of patient data. New disclosures seen by TechCrunch offer the clearest picture of the breach so far, including that nearly 350,000 people have been affected so far.
The New Jersey-based CareCloud stores patient records for more than 45,000 providers across the U.S., including doctors’ offices, hospitals, and other medical practices. As such, the company handles a large amount of sensitive medical and billing data on millions of healthcare patients across the country.
According to a data breach notice filed with California’s attorney general’s office this week, CareCloud said hackers had access to one of its electronic health record data stores for at least six days, between March 10 and March 16. The company said a hacker “claimed to have exfiltrated data from databases.” The company did not say how the hackers made the claim, but it’s not uncommon for hackers to share samples of stolen data with victims alongside a ransom demand to prevent it from being published online.
TechCrunch is unaware of any ransomware or extortion group publicly taking credit for the data breach at CareCloud.
The notice said little about the hack beyond its initial March 27 disclosure to regulators, but confirmed TechCrunch’s earlier report that the hackers broke into the company’s data storage hosted on Amazon Web Services.
TechCrunch has learned that the data breach affects at least 345,000 people across the United States, according to listings with several attorneys general, including those in New Hampshire, Massachusetts, and Texas. TechCrunch has also obtained CareCloud’s disclosure filed with Maine’s attorney general.
The number of affected people is likely to rise as more disclosures are filed with state authorities.
The notices confirm that CareCloud notified authorities that the stolen data included people’s names, postal addresses, and Social Security numbers, as well as government-issued identification numbers, such as passports and driver’s licenses. The notices also say that the stolen data included financial information, such as bank account information and payment card numbers, alongside a wealth of medical and health-related information.
CareCloud chief executive Stephen Snyder did not respond to TechCrunch’s request for comment or to questions about the incident.
The cyberattack targeting CareCloud is the latest in a series of breaches targeting healthcare providers this year, including one at healthcare revenue tech giant TriZetto that affected 3.4 million people, and a month-long breach at New York’s public health provider NYC Health + Hospitals, in which hackers stole 1.8 million people’s health data and thousands of employees’ fingerprint scans.
Last week, U.K.-based tech provider Craneware, which provides accounting and billing software to thousands of U.S. healthcare providers, confirmed hackers stole a “significant volume” of its customers’ data from its servers, raising concerns about a breach involving patient data.
Do you know more about CareCloud’s data breach? Do you work at CareCloud and know about its security practices? Contact this reporter via encrypted message at zackwhittaker.1337 on Signal.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.





