CareCloud Breach Exposes Data of 350,000+ Patients

Hackers accessed a CareCloud AWS environment March 10–16, likely stealing names, Social Security numbers, financial account details and medical records of more than 350,000 patients.

CareCloud reported that hackers accessed one of its Amazon Web Services environments between March 10 and March 16, likely removing personal, financial and medical data for more than 350,000 patients. The intrusion affected an electronic health record environment used by the company’s CareCloud Health division and disrupted services on March 16.

An internal investigation concluded on June 24 that personal, financial and medical information had been compromised. CareCloud filed a notification with the Massachusetts Office of Consumer Affairs and Business Regulation and submitted breach notices to attorneys general in multiple states; those filings show at least 350,000 individuals were affected. The company has not provided a final total or identified the party responsible for the attack.

The notification lists potentially exposed information including names, addresses, Social Security numbers, dates of birth, driver’s license and other government ID numbers, financial account and credit or debit card numbers, and medical and health insurance information.

CareCloud engaged outside cybersecurity experts to investigate and respond. In its notification the company wrote: “CareCloud engaged external cybersecurity experts and, with their assistance, secured the affected environment, eliminated the threat, and confirmed that no persistent unauthorized access remained.” CareCloud is offering up to 24 months of identity theft protection, credit monitoring and ID theft recovery services, which include a $1 million insurance reimbursement benefit.

The company has not disclosed whether any patient-facing systems or clinical operations were interrupted beyond the March 16 disruption, how the attackers gained access to the AWS environment, which specific practices or patients were affected, or whether the stolen data has been posted or sold online. The notification states the company will update affected individuals and regulators as the investigation continues but does not provide a timeline for further disclosures.

Federal and state breach-notification laws require providers and health IT vendors to notify affected individuals and regulators when protected health information is compromised; CareCloud’s filings with state authorities reflect that notification process is underway.

Articles by this author