Hackers Breach CareCloud Systems, Exposing Records of Over 345,000 Patients
AI-generated from multiple sources. Verify before acting on this reporting.
BOSTON — A cyberattack on U.S. health technology firm CareCloud has compromised the medical records and personal data of at least 345,000 patients across multiple states, according to a notification issued Wednesday evening.
The breach targeted patient record stores hosted on Amazon Web Services (AWS) infrastructure managed by CareCloud. The incident affects healthcare providers operating in New Hampshire, Massachusetts, Texas, Maine, and other regions where the company's software is deployed. While the full scope of the data exposure remains under assessment, initial findings indicate that sensitive information including names, dates of birth, social security numbers, and clinical history was accessed by unauthorized actors.
CareCloud confirmed the intrusion on July 30, stating that investigators identified signs of a cyberattack earlier in the week. The company immediately initiated containment measures to secure its systems and engaged cybersecurity experts to analyze the extent of the compromise. No evidence currently suggests that patient care delivery has been disrupted or that financial data was accessed during the incident.
The attack highlights growing vulnerabilities within cloud-based health information exchanges. CareCloud serves hundreds of medical practices, clinics, and hospitals nationwide, making it a significant target for criminal groups seeking to monetize high-value personal health information. The company is notifying affected patients directly and offering credit monitoring services as part of its response protocol.
State attorneys general in Massachusetts and New Hampshire have launched preliminary inquiries into the breach. Officials are reviewing whether CareCloud adhered to state-specific data protection regulations regarding cloud storage and incident reporting timelines. Federal regulators, including officials from the Department of Health and Human Services Office for Civil Rights, may also become involved if federal privacy laws were violated.
The motive behind the attack remains unclear. Cybersecurity analysts note that ransomware groups often target healthcare systems to demand payments in exchange for restoring access or preventing public disclosure of stolen data. However, CareCloud has not confirmed whether a ransom was demanded or paid. The company declined to comment on specific technical details regarding how attackers gained entry into its AWS-hosted environment.
Patients are advised to monitor their financial accounts and credit reports for suspicious activity. Those with concerns about the security of their medical records have been encouraged to contact CareCloud's dedicated support line established for breach-related inquiries.
As investigations continue, questions remain regarding whether additional patient data was exfiltrated beyond the initial 345,000 identified cases. Authorities are also examining if similar attacks may be underway against other healthcare providers using comparable cloud architectures. The incident underscores the ongoing challenges faced by digital health platforms in safeguarding sensitive information against increasingly sophisticated cyber threats.