A major cybersecurity incident involving healthcare technology provider CareCloud is affecting hundreds of thousands of people across the United States, with the company now sending notification letters to individuals whose personal and medical information may have been exposed.

Although the breach was initially disclosed earlier this year, newly released filings provide a much clearer picture of the scale of the incident. Current reports indicate that more than 345,000 people have been impacted, and that number could continue to increase as additional notifications are submitted to state regulators.

Hackers Accessed Patient Data for Several Days

CareCloud, headquartered in New Jersey, provides electronic health record (EHR) and practice management services to more than 45,000 healthcare providers, including hospitals, clinics, and physicians’ offices across the country.

According to recently filed breach notifications, attackers gained unauthorized access to one of the company’s electronic health record databases between March 10 and March 16, giving them several days to access sensitive information. The company stated that the attackers claimed to have copied data from the compromised systems, though it has not publicly explained how that claim was verified.

At this time, no known ransomware or cybercriminal group has publicly accepted responsibility for the attack.

Cloud-Based Storage Was Targeted

The latest disclosures also confirm earlier reports that the compromised database was hosted on Amazon Web Services (AWS). While CareCloud has acknowledged the unauthorized access, the company has released only limited technical details regarding how the attackers entered its systems or whether any security vulnerabilities were exploited.

Information submitted to attorneys general in multiple U.S. states—including California, Maine, Massachusetts, New Hampshire, and Texas—shows that the breach has already reached hundreds of thousands of individuals.

What Information Was Exposed?

The stolen records reportedly contain a wide range of highly sensitive personal and healthcare information.

Compromised data may include:

  • Full names
  • Home mailing addresses
  • Social Security numbers
  • Driver’s license and passport details
  • Bank account information
  • Payment card details
  • Insurance records
  • Medical histories and treatment information
  • Other healthcare-related records

Because the breach includes both financial and medical information, cybersecurity experts warn that affected individuals could face an increased risk of identity theft, financial fraud, and healthcare-related scams.

Investigation Continues

CareCloud has begun notifying affected individuals and regulatory authorities, but the company has not answered several important questions surrounding the incident. Publicly available disclosures also suggest that the overall number of victims may continue to rise as additional investigations are completed.

The breach adds to a growing list of cyberattacks targeting healthcare organizations during 2026. Several major healthcare providers and technology companies have reported similar incidents this year, highlighting the increasing focus of cybercriminals on organizations that store valuable medical and financial records.

With healthcare data remaining one of the most sought-after targets for attackers, this incident serves as another reminder of the importance of strong cybersecurity measures and rapid breach response within the healthcare sector.

Share.
Leave A Reply

Exit mobile version