CareCloud Breach Exposes 350,000 Records
A health IT firm is notifying over 350,000 individuals following an unauthorized access incident within its AWS environment.
A significant security incident has impacted the CareCloud Health division, forcing the company to disclose that sensitive information belonging to hundreds of thousands of people was accessed by unauthorized actors. The breach, which was identified following a disruption to an electronic health record environment on March 16, 2026, involves a wide range of personal and medical data points.
Unauthorized Access to AWS Environments
An internal investigation into the incident revealed that attackers successfully penetrated one of the company's AWS environments. The unauthorized access occurred over a six-day window, starting on March 10, 2026, and lasting until March 16, 2026. While the company stated that it has not found evidence suggesting the stolen information has been misused thus far, the breadth of the compromised data is extensive.
Scope of the Compromised Data
The company confirmed the incident details through a formal notification process, with related documentation also filed with the Massachusetts Office of Consumer Affairs and Business Regulation. The exposed records include:
- Names and residential addresses
- Social Security numbers
- Dates of birth
- Driver's license and government ID numbers
- Financial account and payment card details
- Medical and health insurance records
For a specific subset of victims, the exposure was even more severe, including full credit card information complete with CVV codes.
CareCloud engaged external cybersecurity experts and, with their assistance, secured the affected environment, eliminated the threat, and confirmed that no persistent unauthorized access remained. CareCloud is continuing to strengthen the security of its systems and environments.
— CareCloud, in an incident notification
Response and Identity Protection
To address the aftermath of the intrusion, CareCloud is offering affected individuals up to 24 months of identity theft protection services, including credit monitoring and recovery support. These services are bolstered by a $1,000,000 insurance reimbursement policy designed to provide financial protection to those whose data may have been compromised.
Broader Implications for Data Security
For healthcare providers and their technology vendors, this incident highlights the risks inherent in managing vast quantities of sensitive data within cloud-based infrastructures. As organizations scale their digital footprints, the ability to maintain continuous visibility into cloud environments—and to detect unauthorized activity before data exfiltration occurs—remains a critical hurdle. For consumers, the nature of this breach suggests that the threat extends beyond simple login credentials to include immutable identifiers like Social Security numbers and medical history, which carry long-term risks for identity theft and fraud.
Sources
- SecurityWeek Original source
- filed Also reporting
- notification Also reporting
Continue Reading
KREMLIN Malware Hijacks Chrome and Edge
Elastic Security Labs details a Brazilian banking malware toolkit that abuses browser extension installs and Ethereum smart contracts to steal credentials and sessions.
Iranian Spies Target Windows Users
FBI, UK NCSC, and Dutch AIVD warn that Iranian actors use social messaging apps to deploy Chosen Brick data-stealing malware.
Swiss Court Jails Ransomware Coder 12 Years
A Zurich court found the 52-year-old Ukrainian developer built LockerGoga, MegaCortex, and Nefilim, though not as the operations' mastermind.