CareCloud notifies 345,000 patients after hackers steal medical records

CareCloud data breach exposes 345,000 patients' sensitive medical records, including Social Security numbers and financial data, in a cyberattack on the health tech company.

By Central
The CareCloud breach is one of the largest healthcare data breaches this year, affecting patients across the U.S.
Highlights
  • Hackers accessed CareCloud's electronic health record data store between March 10 and March 16, 2025.
  • Stolen data includes names, Social Security numbers, financial information, and medical records of 345,000 patients.
  • The breach highlights ongoing cybersecurity vulnerabilities in the healthcare sector, with regulators increasing enforcement actions.

Hundreds of thousands of patients across the United States are receiving letters this week informing them that their medical records were stolen in a cyberattack against CareCloud, a major U.S. health technology company, as new disclosures detail the scope and severity of the breach for the first time. The company, which stores and processes sensitive health data for more than 45,000 healthcare providers, has remained largely silent about the incident since it first acknowledged hackers had broken into one of its electronic health record data stores in late March. Now, filings with multiple state attorneys general reveal that at least 345,000 individuals have been affected so far, with the number expected to climb as additional notifications are filed. The breach is the latest in a string of high-profile attacks targeting the healthcare sector this year, underscoring the persistent vulnerability of patient data in an industry that remains a prime target for cybercriminals.

CareCloud Data Breach: What Happened and When

The cyberattack on CareCloud unfolded over a six-day window in March. According to a data breach notice filed with the California attorney general’s office, hackers gained access to one of the company’s electronic health record data stores between March 10 and March 16. The company stated that the attacker “claimed to have exfiltrated data from databases.” While CareCloud did not specify how the claim was communicated, such assertions are typically made alongside a ransom demand, with hackers providing samples of stolen data to pressure victims into paying to prevent publication. No known ransomware or extortion group has publicly taken credit for the breach, and the company has not confirmed whether a ransom was demanded or paid.

CareCloud’s initial disclosure to federal regulators on March 27 provided few details, but later filings confirm that the breach involved data stored on Amazon Web Services, consistent with earlier reporting. The company is a New Jersey-based health technology firm that provides electronic health record (EHR) systems, revenue cycle management, and practice management software to a wide network of healthcare providers, including doctors’ offices, hospitals, and other medical practices across the United States. Because of its central role in managing patient data for tens of thousands of providers, the breach has the potential to affect a far larger population than the 345,000 individuals already identified.

What Patient Data Was Stolen in the CareCloud Attack

The stolen data is extensive and includes some of the most sensitive categories of personal information. Notifications filed with state authorities confirm that the compromised records contained:

  • Names and postal addresses
  • Social Security numbers
  • Government-issued identification numbers, including passport and driver’s license numbers
  • Financial information such as bank account details and payment card numbers
  • A wide range of medical and health-related information

This combination of personally identifiable information, financial data, and protected health information makes the breach particularly dangerous. Victims face not only the risk of medical identity theft—where fraudsters use stolen health data to obtain medical services or prescription drugs—but also financial fraud and long-term identity theft. Social Security numbers and government ID numbers are among the most valuable assets on the black market, and their exposure can lead to years of remediation for affected individuals.

What is the primary risk for patients affected by the CareCloud breach? The primary risk is the potential for both medical identity theft and financial fraud. Because the stolen data includes Social Security numbers, passport numbers, and driver’s license numbers, criminals can use this information to open credit accounts, file fraudulent tax returns, or obtain medical care in someone else’s name. Medical identity theft can be particularly difficult to resolve, as it often involves incorrect entries in medical records that may affect future healthcare decisions.

Why the CareCloud Breach Is Part of a Larger Healthcare Cybersecurity Crisis

The attack on CareCloud is not an isolated incident. It follows a series of major breaches targeting healthcare organizations throughout 2026, revealing systemic weaknesses in how patient data is protected across the industry. In March, TriZetto, a healthcare revenue technology giant, confirmed a breach that affected 3.4 million people. In May, New York’s public health provider NYC Health + Hospitals disclosed that hackers had stolen medical data and employee fingerprints during a month-long breach affecting at least 1.8 million individuals. And just last week, Craneware, a U.K.-based technology provider that supplies accounting and billing software to thousands of U.S. healthcare providers, acknowledged that hackers had stolen a “significant volume” of its customers’ data, raising concerns about patient information.

These breaches share common patterns: attackers exploiting cloud storage misconfigurations, gaining access through compromised credentials, or leveraging vulnerabilities in third-party software. The healthcare sector has become an increasingly attractive target because the data held by hospitals, clinics, and health technology vendors is both highly sensitive and often poorly protected. Unlike financial institutions, which have decades of experience securing transactional data, many healthcare organizations have struggled to implement robust cybersecurity measures while maintaining interoperability and patient access.

CareCloud’s Response and Regulatory Filings

CareCloud’s public response to the breach has been minimal. CEO Stephen Snyder did not respond to requests for comment or to specific questions about the incident. The company has relied on the standard notification process required by state breach notification laws. In addition to the California filing, CareCloud has submitted disclosures to attorneys general in New Hampshire, Massachusetts, Texas, and Maine. These filings are publicly accessible and have provided the clearest picture of the breach to date.

The number of affected individuals—345,000—is based on the disclosures already filed. It is likely to increase as CareCloud continues to identify impacted patients and notify state authorities. Under U.S. state laws, companies must report breaches affecting residents of certain states, and the total number of notifications often rises as more jurisdictions receive filings. The company has not yet disclosed whether all 345,000 individuals have been notified, but the letters are being sent out now.

CareCloud also faces potential regulatory scrutiny. The Health Insurance Portability and Accountability Act (HIPAA) requires covered entities and their business associates to report breaches of protected health information affecting 500 or more individuals to the U.S. Department of Health and Human Services. Failure to do so in a timely manner can result in fines. Additionally, state attorneys general may investigate the breach, particularly if it is found that the company failed to implement reasonable security measures. Given that the hackers accessed data stored on Amazon Web Services, questions may arise about how the company configured its cloud storage and whether appropriate access controls and encryption were in place.

What Affected Patients Should Do Now

For the 345,000 individuals who have received or will receive notification letters, the steps to take are critical and time-sensitive. The stolen data includes Social Security numbers and financial account information, making it essential to act quickly to mitigate potential harm.

  • Place a fraud alert on credit reports with the three major credit bureaus: Equifax, Experian, and TransUnion. A fraud alert makes it harder for identity thieves to open accounts in the victim’s name.
  • Consider a credit freeze, which blocks access to credit reports entirely, preventing new accounts from being opened without explicit authorization.
  • Monitor financial accounts for unauthorized transactions and report any suspicious activity to the bank or card issuer immediately.
  • Review medical records for any signs of fraudulent claims or services billed under the patient’s name. Patients can request a copy of their medical records from their healthcare providers and check for inaccuracies.
  • File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov and consider filing a police report if evidence of identity theft is found.
  • Contact health insurance providers to alert them of the potential for medical identity theft.

Patients should also be cautious of phishing attempts. With detailed personal and medical information now in the hands of attackers, it is likely that victims will receive targeted emails, phone calls, or text messages purporting to be from CareCloud, their healthcare provider, or a government agency. These communications may attempt to extract additional information or trick recipients into clicking malicious links.

Cloud Storage Vulnerabilities and the Healthcare Sector

The CareCloud breach highlights the risks associated with cloud storage in healthcare. The company confirmed that the data was stored on Amazon Web Services, a widely used cloud platform. While AWS provides robust security tools, the responsibility for configuring those tools correctly lies with the customer. Misconfigurations—such as leaving storage buckets publicly accessible, failing to enable encryption, or using weak access controls—are among the most common causes of data breaches in the cloud. It remains unclear exactly how the attackers gained access, but the fact that they had access for six days before detection suggests that monitoring and alerting systems may have been inadequate.

Healthcare organizations have been migrating to cloud-based systems for years, drawn by lower costs and greater scalability. However, this shift has introduced new attack surfaces. Unlike on-premises systems that are physically isolated, cloud environments are accessible from anywhere, and a single compromised credential can lead to a massive data exfiltration. The TriZetto breach earlier this year, which affected 3.4 million people, also involved cloud infrastructure, underscoring a pattern that regulators and industry leaders are struggling to address.

The Craneware breach, disclosed just last week, further illustrates the interconnected nature of healthcare technology. Craneware provides accounting and billing software to thousands of U.S. hospitals and pharmacies. When a technology provider is compromised, the ripple effects can extend to hundreds of downstream healthcare organizations, each with its own patient populations. The CareCloud breach is similar: because the company serves 45,000 providers, the actual number of patients whose data was exposed could be far higher than the 345,000 already identified. Many providers may not even be aware that their patients were affected until they receive notifications from CareCloud or from state authorities.

Who Is Responsible for Protecting Patient Data

Under HIPAA, both healthcare providers and their business associates—companies like CareCloud that handle protected health information on their behalf—are legally responsible for safeguarding patient data. The law requires risk analyses, access controls, encryption, incident response plans, and breach notifications. When a breach occurs, the burden falls on the covered entity to notify affected individuals, the Department of Health and Human Services, and in some cases, the media. But the ultimate accountability often remains unclear, especially when a breach involves a subcontractor or a cloud service provider.

In the CareCloud case, the company is a business associate of thousands of healthcare providers. Those providers may face their own liability if it is determined that they failed to adequately vet CareCloud’s security practices or to contractually require appropriate safeguards. Patients, however, have limited recourse. They cannot directly sue under HIPAA, but they can bring claims under state law for negligence or breach of contract. Class-action lawsuits following healthcare data breaches have become increasingly common, and CareCloud could face significant legal exposure if victims suffer demonstrable harm.

The Broader Implications for Healthcare Cybersecurity

The frequency and severity of healthcare data breaches in 2026 should serve as a wake-up call for the entire industry. Attackers are not only targeting large hospital systems but also the technology vendors that support them. This lateral targeting strategy allows criminals to access data from multiple organizations through a single point of failure. The CareCloud breach, combined with the TriZetto, NYC Health + Hospitals, and Craneware incidents, suggests that the healthcare sector’s cybersecurity posture is not keeping pace with the threat landscape.

Regulators are taking notice. The Office for Civil Rights at the Department of Health and Human Services has increased enforcement actions in recent years, and several state attorneys general have launched investigations into major breaches. Proposed legislation at the federal level would require stronger encryption standards, mandatory breach notification within shorter timeframes, and greater transparency about security practices. However, legislative progress has been slow, and in the meantime, patient data remains at risk.

For healthcare providers, the lesson is clear: relying on third-party vendors without rigorous security assessments is no longer acceptable. Vendor risk management must become a core competency, with regular audits, penetration testing, and contractual obligations that hold business accounts to high standards. For patients, the breach underscores the importance of proactive identity monitoring—not just after a notification, but as a routine practice.

The 345,000 individuals affected by the CareCloud breach may be the first wave, but they will almost certainly not be the last. As healthcare data continues to flow through increasingly complex digital ecosystems, the attack surface will only expand. Without fundamental changes in how the industry approaches cybersecurity—moving from reactive compliance to proactive threat management—the number of patients receiving letters like these will continue to grow. The CareCloud incident is not an anomaly; it is a symptom of a system that has not yet adapted to the realities of a data-driven, cloud-connected healthcare environment.

Share This Article