Electronic health record company CareCloud says 3.7 million people affected by breach
One of the largest hospital technology providers told federal regulators that 3.7 million people were impacted by a data breach in March.
Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments.
In breach notification letters to victims filed in multiple states, CareCloud said a hacker had access to one of their AWS environments from March 10 to March 16 and was able to exfiltrate data.
The stolen data includes personal information, Social Security numbers, ID numbers, credit and debit card information as well as medical information and insurance data.
CareCloud initially reported the attack to law enforcement but by March 24 company officials decided to inform the Securities Exchange Commission (SEC) “in light of the sensitivity of the potentially affected information and the potential consequences of the incident.”
Among the 3.7 million affected, more than 270,000 are in Texas, 23,000 are in South Carolina and nearly 58,000 are in Oregon. New Hampshire, Massachusetts and California did not say how many residents were impacted.
CareCloud is a large provider of technology and software to hospitals and medical practices, serving more than 45,000 providers. They offer electronic health record systems as well as digital revenue and business products. The company reported $120.5 million in revenue in the last fiscal year.
No hacking group took credit for the incident. Large electronic health record companies have been repeatedly targeted by hackers over the last year, including one serving more than 2,000 hospitals in the U.S.
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



