CareCloud begins to notify hundreds of thousands after hackers stole medical records — SkimNews

Get the Health newsletter
Daily health & science — research, biotech, public health, the studies worth knowing. Free.
- CareCloud is notifying approximately 350,000 people that hackers stole their medical records from one of its six electronic health record data stores, with unauthorized access lasting from March 10 to March 16.
- Stolen data includes names, postal addresses, Social Security numbers, government-issued IDs like passports and driver's licenses, bank account information, payment card numbers, and medical and health-related records.
- Filings with attorneys general in New Hampshire, Massachusetts, Texas, and Maine confirm the breach hit CareCloud's data storage hosted on Amazon Web Services, a detail the company had not previously disclosed.
- A hacker "claimed to have exfiltrated data from databases," a pattern consistent with ransom demands accompanied by stolen-data samples, though no ransomware or extortion group has publicly claimed responsibility.
- CareCloud stores records for more than 45,000 U.S. healthcare providers handling millions of patients, and CEO Stephen Snyder did not respond to requests for comment.
- The breach fits a wider pattern: TriZetto's hack affected 3.4 million people, NYC Health + Hospitals lost 1.8 million health records plus employee fingerprint scans in a month-long intrusion, and U.K.-based Craneware recently confirmed a "significant volume" of customer data was stolen from its servers.
Why it matters: CareCloud holds records for 45,000+ U.S. healthcare providers serving millions of patients, so the 350,000 confirmed victims likely represent only a fraction of total exposure as more state disclosures trickle in. Combined with the TriZetto (3.4M), NYC Health + Hospitals (1.8M), and Craneware incidents, healthcare's third-party tech vendors have become a systemic soft target — and no extortion group has even claimed this one yet.
Ask SkimNews




