CareCloud begins to notify hundreds of thousands after hackers stole medical records

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CareCloud is notifying approximately 350,000 people that hackers stole their medical records in a breach first disclosed in March, with the count likely to rise as more state filings are submitted.
- Hackers accessed one of CareCloud's six electronic health record data stores for at least six days between March 10 and March 16, later claiming to have exfiltrated data, according to filings with California's attorney general.
- The stolen data included people's names, postal addresses, Social Security numbers, government IDs (passports and driver's licenses), bank account information, payment card numbers, and extensive medical and health-related information.
- The breach hit data storage hosted on Amazon Web Services, and no ransomware or extortion group has publicly claimed responsibility.
- CEO Stephen Snyder did not respond to TechCrunch's request for comment or questions about the incident.
- The attack extends a wave of healthcare breaches in 2025, including TriZetto (3.4 million affected), NYC Health + Hospitals (1.8 million), and U.K.-based Craneware, which confirmed a "significant volume" of customer data was stolen last week.
Why it matters: With CareCloud storing records for 45,000+ providers nationwide, a single vendor breach compromises patients across thousands of practices simultaneously. The stolen data — SSNs, bank and payment card numbers, government IDs, and medical records — gives attackers comprehensive material for identity theft, and no ransomware group has publicly claimed the breach.




