Particle.news
Download on the App Store

CareCloud Breach Confirmed to Have Exposed 3.76 Million People

Federal records show broad theft of medical and identity data, raising new questions about cloud security and disclosure practices.

Overview

  • A forensic review found an unauthorized party accessed one of CareCloud’s Amazon Web Services environments between March 10 and March 16 and claimed to have exfiltrated databases after the company detected a March 16 network disruption.
  • The Department of Health and Human Services updated its breach tracker to 3,756,469 affected individuals, a figure the agency has confirmed to reporters.
  • The stolen files include names, postal addresses, Social Security numbers, driver’s license numbers, dates of birth, health insurance details, medical records, and a limited set of full payment card data.
  • CareCloud told regulators it determined the incident was material on March 24, filed an SEC Form 8-K on March 27, notified state attorneys general, and is offering identity-theft protection to affected people with enrollment open through Dec. 17.
  • No group has publicly claimed responsibility and CareCloud has not confirmed any ransom payment, and the large jump from state AG filings to the HHS total has intensified scrutiny of health vendors’ cloud security and reporting practices this year.