Friday, July 31, 2026

Independent technology reporting and practical analysis

Manila ·
CYBERSECURITY

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Cybersecurity / news

CareCloud Data Breach Exposes Medical Records of 345,000 Patients

U.S. health tech firm CareCloud is notifying hundreds of thousands that hackers accessed an electronic health record store for six days in March, stealing sensitive personal and medical data.

Open-source medical security shield icon representing protection of healthcare records. Icon by Lucide.
Open-source medical security shield icon representing protection of healthcare records. Icon by Lucide.

CareCloud, a U.S. health technology company that manages patient records for over 45,000 healthcare providers, has begun notifying around 345,000 individuals that their medical and personal data was stolen in a cyberattack earlier this year, according to state regulatory filings obtained by TechCrunch.

The breach occurred between March 10 and 16, 2025, when an unauthorized party accessed one of CareCloud’s electronic health record data stores hosted on Amazon Web Services. TechCrunch previously reported on the intrusion, which the company initially disclosed to regulators on March 27, but the new filings provide the most detailed account to date.

CareCloud’s data breach notice filed with the California attorney general’s office states that a hacker “claimed to have exfiltrated data from databases.” The company did not elaborate on how the claim was made, though it is common for attackers to share stolen data samples as part of ransom demands. No ransomware or extortion group has publicly taken credit for the incident, TechCrunch reports.

The stolen information includes full names, postal addresses, Social Security numbers, government-issued identification such as passport and driver’s license details, financial information like bank account and payment card numbers, and an extensive range of medical and health-related data. The exact number of affected individuals may increase as additional state disclosures are filed.

CareCloud, headquartered in New Jersey, provides electronic health records, practice management, and billing services to doctors’ offices, hospitals, and other medical practices nationwide. The company handles highly sensitive information on millions of patients across the country.

CareCloud chief executive Stephen Snyder did not respond to TechCrunch’s request for comment on the breach or the company’s security practices.

The attack on CareCloud is part of a growing wave of cyber incidents targeting the U.S. healthcare sector this year. Other recent breaches include a hack at healthcare revenue technology firm TriZetto that compromised data on 3.4 million people and a month-long intrusion at NYC Health + Hospitals that exposed 1.8 million patients’ health records and thousands of employee fingerprint scans. Additionally, U.K.-based Craneware, which supplies accounting software to U.S. healthcare providers, confirmed last week that hackers stole a “significant volume” of customer data from its servers, prompting concerns over patient information exposure.

TechCrunch security editor Zack Whittaker contributed reporting.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Spotify brand mark in green, used to represent the Running Mode feature. Brand icon via Simple Icons.
Software

Spotify’s New Running Mode Uses AI to Curate Workout Playlists

Xbox brand logo representing the console service outage. Brand icon via Simple Icons.
Gaming

Xbox Outage Prevents Disc-Based Play, Fueling Digital Ownership Fears

Google Play brand mark representing the Play Signal API. Brand icon via Simple Icons.
Software

Google to Roll Out Play Signal API Globally by End of 2026 for Age Assurance