Particle.news
Download on the App Store

CareCloud Breach Exposes Records of About 3.76 Million Patients

The cloud intrusion heightens identity theft risk for millions of patients by exposing personal, government and medical identifiers to unknown actors.

Overview

  • A forensic probe found an unauthorized party accessed one of CareCloud’s Amazon Web Services environments between March 10 and March 16 and claimed to have exfiltrated data from databases there.
  • The company reported to federal regulators in late March and HHS updated its breach tracker in mid‑August to show 3,756,469 affected individuals.
  • Stolen records include full names, addresses, dates of birth, Social Security numbers, driver’s license or passport numbers, medical and insurance information, and for a limited subset full payment card data.
  • CareCloud began mailing notification letters on July 25 and is offering identity‑protection services with enrollment open through Dec. 17 while investigations and regulatory follow‑up continue.
  • No group has publicly claimed responsibility and the company has not said whether a ransom was paid, raising ongoing legal, financial and fraud risks for patients and the healthcare providers that rely on CareCloud.