A whole lot of 1000’s of individuals are receiving letters notifying them that their medical information have been stolen in a cyberattack at U.S. well being tech big CareCloud earlier this 12 months, as new particulars concerning the knowledge breach come to mild.
The corporate has mentioned little concerning the breach since March, when it first admitted that hackers had raided one of its six stores of patient data. New disclosures seen by TechCrunch provide the clearest image of the breach to this point, together with that just about 350,000 individuals have been affected to this point.
The New Jersey-based CareCloud shops affected person information for greater than 45,000 suppliers throughout the U.S., together with medical doctors’ places of work, hospitals, and different medical practices. As such, the corporate handles a considerable amount of delicate medical and billing knowledge on tens of millions of healthcare sufferers throughout the nation.
Based on a data breach notice filed with California’s lawyer common’s workplace this week, CareCloud mentioned hackers had entry to certainly one of its digital well being report knowledge shops for a minimum of six days, between March 10 and March 16. The corporate mentioned a hacker “claimed to have exfiltrated knowledge from databases.” The corporate didn’t say how the hackers made the declare, however it’s not unusual for hackers to share samples of stolen knowledge with victims alongside a ransom demand to forestall it from being printed on-line.
TechCrunch is unaware of any ransomware or extortion group publicly taking credit score for the info breach at CareCloud.
The discover mentioned little concerning the hack past its initial March 27 disclosure to regulators, however confirmed TechCrunch’s earlier report that the hackers broke into the corporate’s knowledge storage hosted on Amazon Internet Companies.
TechCrunch has discovered that the info breach impacts a minimum of 345,000 individuals throughout the USA, in response to listings with a number of attorneys common, together with these in New Hampshire, Massachusetts, and Texas. TechCrunch has additionally obtained CareCloud’s disclosure filed with Maine’s lawyer common.
The variety of affected individuals is prone to rise as extra disclosures are filed with state authorities.
The notices verify that CareCloud notified authorities that the stolen knowledge included individuals’s names, postal addresses, and Social Safety numbers, in addition to government-issued identification numbers, comparable to passports and driver’s licenses. The notices additionally say that the stolen knowledge included monetary info, comparable to checking account info and fee card numbers, alongside a wealth of medical and health-related info.
CareCloud chief government Stephen Snyder didn’t reply to TechCrunch’s request for remark or to questions concerning the incident.
The cyberattack focusing on CareCloud is the newest in a collection of breaches focusing on healthcare suppliers this 12 months, together with one at healthcare income tech big TriZetto that affected 3.4 million people, and a month-long breach at New York’s public well being supplier NYC Well being + Hospitals, wherein hackers stole 1.8 million people’s health data and 1000’s of staff’ fingerprint scans.
Final week, U.Okay.-based tech supplier Craneware, which gives accounting and billing software program to 1000’s of U.S. healthcare suppliers, confirmed hackers stole a “significant volume” of its customers’ data from its servers, elevating issues a few breach involving affected person knowledge.
Are you aware extra about CareCloud’s knowledge breach? Do you’re employed at CareCloud and find out about its safety practices? Contact this reporter by way of encrypted message at zackwhittaker.1337 on Sign.
Whenever you buy by hyperlinks in our articles, we may earn a small commission. This doesn’t have an effect on our editorial independence.

