9 days ago
TechCrunch Jul 30, 2026

CareCloud begins to notify hundreds of thousands after hackers stole medical records

CareCloud, a major U.S. health technology company, has begun notifying hundreds of thousands of individuals after a cyberattack compromised one of its protected electronic health record data stores earlier this year. The breach, which took place between March 10 and 16, exposed sensitive medical and billing data from patients served by over 45,000 healthcare providers nationwide. To date, nearly 350,000 people have been confirmed affected, with notifications being filed across multiple state attorney general offices including California, New Hampshire, Massachusetts, Texas, and Maine.

The hacked data includes names, postal addresses, Social Security numbers, government-issued IDs like passports and driver’s licenses, as well as financial details including bank account and payment card numbers. The exact hacking method has not been disclosed, but hackers reportedly claimed to have exfiltrated data, a tactic often associated with ransom demands. The breach was linked to CareCloud’s data storage hosted on Amazon Web Services, confirming earlier reports of unauthorized access to one of six patient data repositories managed by the company.

This incident adds to a troubling trend of cyberattacks targeting healthcare entities in 2026, following large-scale breaches at firms like TriZetto, which affected 3.4 million people, and NYC Health + Hospitals, which lost data on 1.8 million individuals along with fingerprint scans of thousands of employees. CareCloud’s CEO, Stephen Snyder, has not publicly commented on the attack. The healthcare sector continues to face increasing pressure to bolster cybersecurity practices amid growing risks to sensitive patient information.

The CareCloud breach highlights the ongoing vulnerabilities within healthcare data management and emphasizes the critical need for more robust security measures in this sector. As disclosures continue to emerge, potentially increasing the number of affected individuals, regulatory scrutiny and patient concern are expected to intensify. This attack also serves as a stark reminder of the stakes involved when vast amounts of sensitive personal and medical data are aggregated in cloud-hosted environments without sufficient defenses.

0
0 Read source
Share this post
Facebook Twitter LinkedIn

Discussion

0 comments

No comments yet

Start the discussion with a take, question, or market read.