CareCloud, a healthcare technology company, disclosed that a data security incident earlier this year exposed sensitive personal information of more than 3.7 million individuals.
Headquartered in Somerset, New Jersey, CareCloud is a healthcare technology company providing cloud-based software and outsourced billing services to medical practices and health systems. Its EHR, practice management, and revenue cycle management solutions serve more than 45,000 healthcare providers nationwide, giving the company access to sensitive medical and billing information of millions of patients.
In a filing with California’s attorney general, CareCloud said hackers accessed one of its electronic health record databases for six days, from March 10 to March 16. During this period, an attacker claimed to have extracted data from the company’s systems, although the filing did not disclose how the claim was communicated.
The compromised system was hosted on Amazon Web Services infrastructure. The stolen information includes patients’ full names, addresses and Social Security numbers, along with government identification numbers such as driver’s license and passport numbers. Financial details, including bank account information and payment card numbers, were also exposed, alongside a broad range of medical and health-related records.
Initially, CareCloud reported that nearly 350,000 people were affected, based on disclosures filed with attorneys general in several states, including New Hampshire, Massachusetts, Texas, and Maine. However, in a recent filing with the U.S. Department of Health and Human Services the healthcare technology company said the incident has impacted as many as 3,756,469 people.
“Upon discovering the incident, CareCloud quickly launched an investigation and took steps to contain and remediate the issue. CareCloud engaged external cybersecurity experts and, with their assistance, secured the affected environment, eliminated the threat, and confirmed that no persistent unauthorised access remained. CareCloud is continuing to strengthen the security of its systems and environments,” CareCloud said.
Although the healthcare data management company found no indication that the exposed information had been misused, it urged affected individuals to remain vigilant by regularly reviewing their credit reports, account and benefits statements, and to report any suspicious activity to law enforcement agencies, including local police and the state attorney general.
It has also offered complimentary credit monitoring services through IDX to all affected individuals.
At the time of publishing, no known hacker group claimed responsibility for the cyber attack on CareCloud. The company also did not details on who was behind the attack, how much data was compromised, or whether it has received a ransom demand.
Already have an account? Sign in
Winston House, 3rd Floor, Units 306-309, 2-4 Dollis park, London, N3 1HF
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
