CareCloud stayed largely quiet for months after hackers entered one of its patient-data stores.
Now, breach notices show at least 345,000 people may have had medical, financial, and identity information stolen, with the count expected to climb.
TL;DR
- Attackers accessed an electronic health record repository from March 10 to March 16.
- At least 345,000 people are affected, with more state disclosures likely to raise the total.
- Exposed data included Social Security numbers, payment details, government IDs, and medical information.
- No ransomware or extortion group has publicly claimed responsibility.
CareCloud Data Breach Exposes Records Across Its Healthcare Network
The New Jersey-based health technology provider stores patient records for more than 45,000 U.S. healthcare providers, including hospitals, medical practices, and doctors’ offices.
That scale gives CareCloud access to sensitive medical and billing information belonging to millions of patients.
According to a notification filed with the California Attorney General, attackers accessed one electronic health record data store for at least six days, from March 10 through March 16. CareCloud said a hacker “claimed to have exfiltrated data from databases,” but did not explain how the attacker gained access or made the claim.
Regulatory notices indicate that the affected repository was hosted in Amazon Web Services. No known ransomware or extortion group has publicly taken responsibility.
CareCloud Breach Count Reaches 345,000 And Could Rise Further
Disclosures filed with officials in New Hampshire, Massachusetts, Texas, Maine, and other states show at least 345,000 people are affected. The number is nearing 350,000 and may increase as additional notifications are submitted.
The stolen information included names, mailing addresses, Social Security numbers, passport details, driver’s license numbers, bank account information, payment card numbers, plus medical and clinical data. The exposure creates risks ranging from financial fraud and identity theft to healthcare privacy violations.
CareCloud CEO Stephen Snyder did not respond to requests for comment.
Topics For More Insights
Healthcare Cybersecurity Pressure Builds After Major Patient Data Breaches
The CareCloud incident follows other large healthcare breaches, including TriZetto, which affected more than 3.4 million people, and NYC Health + Hospitals, where a prolonged breach affected 1.8 million patients and exposed thousands of employee fingerprints.
These incidents are increasing pressure on healthcare providers and technology vendors to strengthen cloud security, improve audits, monitor threats, train staff, and notify patients and regulators faster. Protecting patient data is central to maintaining trust in healthcare systems.

