CareCloud, a U.S. health technology company that manages patient records for over 45,000 healthcare providers, has begun notifying around 345,000 individuals that their medical and personal data was stolen in a cyberattack earlier this year, according to state regulatory filings obtained by TechCrunch.
The breach occurred between March 10 and 16, 2025, when an unauthorized party accessed one of CareCloud’s electronic health record data stores hosted on Amazon Web Services. TechCrunch previously reported on the intrusion, which the company initially disclosed to regulators on March 27, but the new filings provide the most detailed account to date.
CareCloud’s data breach notice filed with the California attorney general’s office states that a hacker “claimed to have exfiltrated data from databases.” The company did not elaborate on how the claim was made, though it is common for attackers to share stolen data samples as part of ransom demands. No ransomware or extortion group has publicly taken credit for the incident, TechCrunch reports.
The stolen information includes full names, postal addresses, Social Security numbers, government-issued identification such as passport and driver’s license details, financial information like bank account and payment card numbers, and an extensive range of medical and health-related data. The exact number of affected individuals may increase as additional state disclosures are filed.
CareCloud, headquartered in New Jersey, provides electronic health records, practice management, and billing services to doctors’ offices, hospitals, and other medical practices nationwide. The company handles highly sensitive information on millions of patients across the country.
CareCloud chief executive Stephen Snyder did not respond to TechCrunch’s request for comment on the breach or the company’s security practices.
The attack on CareCloud is part of a growing wave of cyber incidents targeting the U.S. healthcare sector this year. Other recent breaches include a hack at healthcare revenue technology firm TriZetto that compromised data on 3.4 million people and a month-long intrusion at NYC Health + Hospitals that exposed 1.8 million patients’ health records and thousands of employee fingerprint scans. Additionally, U.K.-based Craneware, which supplies accounting software to U.S. healthcare providers, confirmed last week that hackers stole a “significant volume” of customer data from its servers, prompting concerns over patient information exposure.
TechCrunch security editor Zack Whittaker contributed reporting.
See an error? Read our corrections policy or email [email protected].
TECHNOMALIST