CareCloud Discloses Data Breach Affecting 345,000 People After AWS-Hosted System Attack

Views: 68 views

419/69 Tuesday, August 4, 2026

CareCloud, a healthcare technology company based in New Jersey, United States, has disclosed a data breach affecting approximately 345,000 people after attackers stole medical and financial data from systems hosted by the company on Amazon Web Services (AWS). CareCloud provides Electronic Health Records (EHR), practice management systems, revenue cycle management, billing, and AI-powered software for hospitals and healthcare providers across the United States. The company also stores patient data for more than 45,000 healthcare providers.

According to a data breach notification filed with the Attorney General’s Office, threat actors accessed one of CareCloud’s Electronic Health Record data stores for at least six days between March 10 and March 16, 2026. The company stated that an unauthorized third party accessed CareCloud’s AWS environment and claimed to have exfiltrated data from a database within that environment. However, CareCloud said it has found no evidence of unauthorized activity within the company’s environment after March 16, 2026. The company has not disclosed technical details of the incident, and no group has claimed responsibility for the attack at the time of reporting.

The information that may have been affected includes names, addresses, Social Security numbers (SSNs), government-issued identification numbers such as passport and driver’s license numbers, bank account details, payment card numbers, and a large volume of medical and health information. This data is highly sensitive and could be used for identity theft or health insurance fraud. The incident occurred amid a continued trend of attacks targeting healthcare data. Previously, Cognizant’s TriZetto Provider Solutions disclosed a data breach affecting 3.4 million people, while Craneware, a billing software provider, also confirmed that a large amount of data belonging to hospital and pharmacy customers had been stolen.

Source: https://securityaffairs.com/196480/cyber-crime/carecloud-breach-exposes-medical-and-financial-data-of-345000.html