Technology

CareCloud Notifies 345,000+ After Hackers Exfiltrate Medical Records From AWS-Hosted EHR Store

Martin HollowayPublished 13h ago4 min readBased on 5 sources
Reading level
CareCloud Notifies 345,000+ After Hackers Exfiltrate Medical Records From AWS-Hosted EHR Store

CareCloud, a New Jersey-based electronic health records provider, has begun notifying hundreds of thousands of individuals that their personal and medical data was stolen in a breach discovered earlier this year. The incident affects at least 345,000 people across the United States, according to filings with the attorneys general of New Hampshire, Massachusetts, Texas, and Maine TechCrunch.

Hackers had access to one of CareCloud's six patient data stores for six days, between March 10 and March 16, 2026. The breached store was hosted on Amazon Web Services. The company disclosed the incident to the U.S. Securities and Exchange Commission in a Form 8-K filing dated March 27, 2026, which states that CareCloud experienced unauthorized access on March 16 SEC Filing. TechCrunch first reported on the breach on March 31, 2026.

CareCloud filed a data breach notice with the California Attorney General's office in the week of July 30, 2026. The California AG's data breach portal lists the breach date as March 10, 2026 and the report date as July 25, 2026 California AG Portal. A hacker claimed to have exfiltrated data from CareCloud's databases, and the scope of stolen information is extensive: names, postal addresses, Social Security numbers, government-issued identification numbers including passport numbers and driver's license numbers, financial information including bank account and payment card numbers, and medical and health-related information.

As of July 30, 2026, no ransomware or extortion group had publicly claimed credit for the breach. CareCloud CEO Stephen Snyder did not respond to TechCrunch's request for comment. CareCloud stores patient records for more than 45,000 healthcare providers across the U.S., including doctors' offices, hospitals, and other medical practices.

The four-month gap between the SEC disclosure in late March and the state-level breach notifications in late July is consistent with the timeline allowed under HIPAA's Breach Notification Rule, which permits covered entities up to 60 days from discovery to notify affected individuals, with state-specific requirements layering additional obligations. The California AG filing on July 25, more than 60 days after the March 16 access date, falls within the regulatory window but raises questions about how the 60-day clock was calculated from the company's perspective on discovery versus confirmed exfiltration.

The data categories involved here represent a near-complete identity theft profile. Social Security numbers, financial account details, and government-issued ID numbers, combined with medical information, give a threat actor the raw material for synthetic identity fraud, medical identity theft, and traditional financial fraud. Medical data is particularly valuable in illicit markets precisely because it cannot be invalidated the way a compromised credit card can be reissued.

Worth flagging is the architecture: six separate patient data stores, with one breached. That suggests segmentation across distinct storage environments, which may have limited the blast radius. The fact that the breached store sat on AWS rather than on-premises infrastructure is not itself notable, but it does mean the attack vector likely involved compromised credentials, misconfigured permissions, or exploited API access rather than network intrusion into CareCloud's own infrastructure. The absence of a claimed ransomware or extortion group at this stage could indicate a data-only exfiltration operation, where the monetization path is resale rather than ransom negotiation.

For the 45,000-plus provider organizations whose patient data flows through CareCloud, the breach downstream impact is significant. Patients whose data was stolen face individual risk, but the providers themselves bear compliance and reputational exposure. In this author's view, the incident reinforces a structural tension in healthcare technology: centralizing patient records across tens of thousands of practices into a handful of shared platforms creates operational efficiencies that also concentrate risk. A single breach at one EHR vendor can ripple across the patient bases of every practice that depends on it.

CareCloud has not publicly detailed the specific access vector, remediation steps taken since March, or whether the other five data stores were investigated for compromise. The company's SEC filing confirmed unauthorized access but the full technical scope may not be clear until additional state filings or regulatory actions surface.