Data belonging to 3.75 million patients was exposed in the CareCloud breach – not the 350,000 originally reported
The number of victims in the CareCloud breach has surged to over three and a half million
The number of victims affected in the CareCloud breach has been revised from 350,000 to roughly 3.75 million, the company has revealed.
The American medical record storage first confirmed it had been breached back in March, with hackers gaining access to medical data held in its cloud over six whole days.
According to regulatory filings from CareCloud at the time, the intrusion was spotted on 16 March. An investigation into the incident found an unauthorized party had gained access to an AWS environment for several days.
The initial filing said the attack caused a network outage of eight hours, disrupting access to the impacted database.
CareCloud noted the hackers "claimed to have exfiltrated data from databases within that environment", though the nature of the attack and whether CareCloud was directly communicating with the attackers remains unclear.
Reports suggest no hacking group has as yet claimed responsibility for the attack.
After CareCloud spotted the incident, access was shut down and no further unauthorized activity was spotted.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
CareCloud breach notices cited far lower victim numbers
In July, disclosure letters were distributed to around 350,000 people in the US who were believed to be affected — but that has since risen to 3.75 million potential victims.
Leaked data includes names and addresses, as well as more sensitive details such as bank accounts, payment card numbers, medical data, and government identification including driver's licenses, passports, and Social Security numbers.
Ross Filipek, CISO at Corsica Technologies, said the revision to the victim list highlights the disastrous impact of cyber attacks on healthcare organizations – which rank among the top targets for cyber criminals.
"This isn't just a massive breach of data, it's a warning," Filipek commented. "Nearly four million patients having their information exposed shows just how much sensitive data can be concentrated behind a single healthcare technology provider."
"It also creates significant legal and regulatory exposure for a provider handling this much protected health information, which could make the fallout expensive for CareCloud."
What's next?
CareCloud hasn't revealed much detail about the attack – including whether it was ransomware or a ransom was paid – but the company says its continuing to investigate and lockdown systems.
"Upon discovering the incident, CareCloud quickly launched an investigation and took steps to contain and remediate the issue," a spokesperson said, per reports from Teiss.
"CareCloud engaged external cybersecurity experts and, with their assistance, secured the affected environment, eliminated the threat, and confirmed that no persistent unauthorized access remained. CareCloud is continuing to strengthen the security of its systems and environments."
ITPro approached CareCloud for comment, but did not receive a response by time of publication.
Disclosure letters distributed to affected patients note the company has seen no attempts at identity fraud to date, but warns recipients to be mindful of misuse of the stolen information.
Data exposed in the breach gives cyber criminals “plenty to work with long after the initial incident is over,” Filipek said.
Hackers often use exposed information such as email addresses and phone numbers in follow-up scams in the wake of a cyber attack or breach.
"For patients, the risk doesn’t stop at identity theft," noted Filipek. "Stolen health information can fuel highly convincing phishing, medical fraud, and other scams built around deeply personal details."
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.
Nicole the author of a book about the history of technology, The Long History of the Future.
-
The National Vulnerability Database needs redesigned with machine-speed in mindNews The National Vulnerability Database was designed for human-speed. Advances in AI mean it needs a much-needed overhaul
-
Off-grid: networks cut the cordOpinion Faster, more robust wireless connections offer alternatives to the LAN and public hotspots. But how do IT leaders navigate their way through 5G, 6G, and satellite technology?
-
Health tech firm Craneware admits “significant volume” of customer and employee data exposed in cyber attackNews The incident has been contained and Craneware has launched a probe into the breach
-
Resilient pharmacy care, safeguarding vital health services -
US healthcare firm postponed procedures after cyber attack knocked systems offlineNews The incident at Kettering Health disrupted procedures for patients
-
US healthcare data breaches are out of control – over 400 million patient records have been exposed in the last two yearsNews There's been a huge surge in the number of healthcare data breaches in recent years
-
More than 5 million Americans just had their personal information exposed in the Yale New Haven Health data breach – and lawsuits are already rolling inNews A data breach at Yale New Haven Health has exposed data belonging to millions of people – and lawsuits have already been filed.
-
Healthcare organizations are turning a blind eye to phishing attacksNews A survey reveals that most attacks go unreported, putting patient data at risk
-
Healthcare systems are rife with exploits — and ransomware gangs have noticedNews Nearly nine-in-ten healthcare organizations have medical devices that are vulnerable to exploits, and ransomware groups are taking notice.
-
More than 300,000 US healthcare patients impacted in suspected Rhysida cyber attacksNews Two US healthcare organizations have warned threat actors were able to breach their internal systems, exposing more than 300,000 individuals.