CareCloud Confirms Data Breach Impacting 3.7 Million, Exposing Sensitive Personal and Medical Information

Published:

spot_img

CareCloud, a prominent healthcare software provider, has confirmed that a data breach in March has impacted approximately 3.7 million individuals. The company reported to the Department of Health and Human Services that a hacker accessed its electronic health record environment for eight hours, leading to the exfiltration of sensitive data.

According to reporting by The Record, the breach occurred between March 10 and March 16, during which the attacker gained access to one of CareCloud’s AWS environments. The compromised data includes personal information, Social Security numbers, credit and debit card details, as well as medical and insurance information.

CareCloud initially notified law enforcement about the incident but later informed the Securities Exchange Commission (SEC) on March 24, citing the sensitivity of the affected information and the potential consequences of the breach. Among those affected, over 270,000 individuals are from Texas, 23,000 from South Carolina, and nearly 58,000 from Oregon. The exact number of impacted individuals in New Hampshire, Massachusetts, and California remains undisclosed.

As a major provider of technology and software to healthcare facilities, CareCloud serves over 45,000 providers and reported $120.5 million in revenue in the last fiscal year. Notably, no hacking group has claimed responsibility for this incident, which reflects a troubling trend of cyberattacks targeting large electronic health record companies in recent months.

The investigation into the breach is ongoing, and CareCloud is likely to face scrutiny regarding its data protection measures and response to the incident.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

spot_img

Related articles

Recent articles

Logitech Enhances Hybrid Workplaces in IMEA with AI-Driven Collaboration Solutions

Logitech's AI-Driven Solutions Transform Hybrid Workplaces in IMEA Logitech is advancing the concept of hybrid workplaces across the India, Middle East, and Africa (IMEA) region...

U.S. Agencies Warn of AI-Driven Cyber Attacks Targeting Siemens PLCs in Critical Infrastructure

U.S. government agencies have issued a warning about hackers targeting critical infrastructure, specifically Siemens S7 Series programmable logic controllers (PLCs), using artificial intelligence in...

libheif vulnerabilities could lead to denial of service in Ubuntu 25.10

Security Advisory: libheif Vulnerabilities in Ubuntu 25.10 Recent security findings have identified two significant vulnerabilities in the libheif library, which could lead to denial of...

StopAndProtect Operation Exploits Thousands of Hacked WordPress Sites for Data Theft

Research by: Jaromír Hořejší (@JaromirHorejsi) StopAndProtect Operation: A New Threat Landscape The StopAndProtect operation has emerged as a significant threat, exploiting thousands of compromised WordPress sites...