ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

CareCloud data breach exposes medical records of nearly 350,000 patients

Hundreds of thousands of patients are receiving breach notification letters this week after hackers stole medical records from CareCloud, a New Jersey-based health technology company that manages patient data for tens of thousands of medical providers nationwide.


Nearly 350,000 people have been confirmed affected so far, based on disclosures filed with attorneys general in multiple states, including New Hampshire, Massachusetts, Texas and Maine. That figure is expected to climb as additional states receive notice of the incident.


CareCloud provides electronic health record services to more than 45,000 healthcare providers across the country, including physician offices, hospitals and other medical practices, giving it access to sensitive medical and billing information for millions of patients nationwide.


A filing submitted to California’s attorney general this week states that hackers maintained access to one of CareCloud’s electronic health record databases for six days, from March 10 to March 16. During that window, an attacker claimed to have extracted data from the company’s systems, though the filing does not specify how that claim was communicated. No ransomware or extortion group has publicly claimed responsibility for the intrusion.


The compromised system was hosted on Amazon Web Services infrastructure. The stolen information includes patients’ full names, home addresses and Social Security numbers, along with government identification numbers such as driver’s license and passport numbers. Financial details, including bank account information and payment card numbers, were also exposed, alongside a broad range of medical and health-related records.


CareCloud first disclosed the breach to regulators on March 27 but has released few additional details publicly since then. Chief executive Stephen Snyder did not respond to a request for comment on the incident.


The intrusion adds to a string of cyberattacks that have struck the healthcare sector this year. Revenue technology firm TriZetto disclosed a breach affecting 3.4 million people, while New York City’s public hospital system, NYC Health + Hospitals, experienced a monthlong intrusion in which hackers accessed 1.8 million patients’ health records along with fingerprint scans belonging to thousands of employees. Separately, U.K.-based billing software provider Craneware confirmed last week that hackers had stolen a substantial volume of customer data from its servers, raising further concerns about exposure of patient information across the healthcare technology supply chain.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543