AI & TechBusinessCybersecurityNewswireTechnology

CareCloud notifies hundreds of thousands after medical records stolen in hack

▼ Summary

– Nearly 350,000 people are affected by a cyberattack at health tech giant CareCloud, where hackers stole medical records and personal data.
– Hackers accessed one of CareCloud’s electronic health record data stores for at least six days, between March 10 and March 16.
– Stolen data includes names, postal addresses, Social Security numbers, government ID numbers, financial information, and medical data.
– The breach occurred in data storage hosted on Amazon Web Services, as confirmed by a recent notice.
– No ransomware or extortion group has publicly claimed responsibility for the attack.

Hundreds of thousands of individuals are now receiving notification letters that their medical records were stolen in a cyberattack on U.S. health tech giant CareCloud earlier this year, with fresh details about the data breach finally emerging.

The company has remained largely silent about the incident since March, when it first acknowledged that hackers had breached one of its six patient data repositories. New disclosures obtained by TechCrunch now provide the most comprehensive view yet of the attack, revealing that nearly 345,000 people have been affected so far.

Based in New Jersey, CareCloud stores patient records for over 45,000 healthcare providers across the country, including physician practices, hospitals, and other medical facilities. This means the company handles vast amounts of sensitive medical and billing information for millions of patients nationwide.

According to a data breach notice filed this week with California’s attorney general, hackers had access to one of CareCloud’s electronic health record data stores for at least six days, from March 10 to March 16. The company stated that an attacker “claimed to have exfiltrated data from databases.” CareCloud did not specify how the claim was communicated, though it is common for hackers to share stolen data samples with victims while demanding a ransom to prevent public release.

No ransomware or extortion group has publicly taken responsibility for the CareCloud breach, according to TechCrunch’s knowledge.

The notice offered few new details beyond the company’s initial March 27 disclosure to regulators, but it did confirm TechCrunch’s earlier report that the hackers gained access to data stored on Amazon Web Services.

TechCrunch has discovered that the breach impacts at least 345,000 individuals across the United States, based on filings with attorneys general in New Hampshire, Massachusetts, and Texas. The outlet also obtained CareCloud’s disclosure submitted to Maine’s attorney general.

The total number of affected people is expected to climb as more state authorities receive filings.

The notifications confirm that the stolen data includes names, postal addresses, and Social Security numbers, as well as government-issued identification numbers like passport and driver’s license details. Financial information, including bank account numbers and payment card data, was also taken, alongside a broad range of medical and health-related records.

CareCloud CEO Stephen Snyder did not respond to TechCrunch’s request for comment or to questions about the incident.

This attack on CareCloud is part of a troubling pattern of healthcare data breaches this year. Notable examples include a breach at TriZetto, a healthcare revenue technology firm, which affected 3.4 million people, and a month-long intrusion at NYC Health + Hospitals, where hackers stole 1.8 million individuals’ health data and thousands of employee fingerprint scans.

Last week, U. K.-based technology provider Craneware, which supplies accounting and billing software to thousands of U. S. healthcare organizations, confirmed that hackers had stolen a “significant volume” of customer data from its servers, raising further concerns about potential patient data exposure.

(Source: TechCrunch)

Topics

data breach 95% healthcare cybersecurity 92% stolen data types 90% patient privacy 88% affected individuals 85% Ransomware 80% cloud security 78% Regulatory Compliance 75% healthcare industry 74% cyberattack timeline 72%