CareCloud Breach Exposes 350,000 Records
A health IT firm is notifying over 350,000 individuals following an unauthorized access incident within its AWS environment.
A significant security incident has impacted the CareCloud Health division, forcing the company to disclose that sensitive information belonging to hundreds of thousands of people was accessed by unauthorized actors. The breach, which was identified following a disruption to an electronic health record environment on March 16, 2026, involves a wide range of personal and medical data points.
Unauthorized Access to AWS Environments
An internal investigation into the incident revealed that attackers successfully penetrated one of the company's AWS environments. The unauthorized access occurred over a six-day window, starting on March 10, 2026, and lasting until March 16, 2026. While the company stated that it has not found evidence suggesting the stolen information has been misused thus far, the breadth of the compromised data is extensive.
Scope of the Compromised Data
The company confirmed the incident details through a formal notification process, with related documentation also filed with the Massachusetts Office of Consumer Affairs and Business Regulation. The exposed records include:
- Names and residential addresses
- Social Security numbers
- Dates of birth
- Driver's license and government ID numbers
- Financial account and payment card details
- Medical and health insurance records
For a specific subset of victims, the exposure was even more severe, including full credit card information complete with CVV codes.
CareCloud engaged external cybersecurity experts and, with their assistance, secured the affected environment, eliminated the threat, and confirmed that no persistent unauthorized access remained. CareCloud is continuing to strengthen the security of its systems and environments.
— CareCloud, in an incident notification
Response and Identity Protection
To address the aftermath of the intrusion, CareCloud is offering affected individuals up to 24 months of identity theft protection services, including credit monitoring and recovery support. These services are bolstered by a $1,000,000 insurance reimbursement policy designed to provide financial protection to those whose data may have been compromised.
Broader Implications for Data Security
For healthcare providers and their technology vendors, this incident highlights the risks inherent in managing vast quantities of sensitive data within cloud-based infrastructures. As organizations scale their digital footprints, the ability to maintain continuous visibility into cloud environments—and to detect unauthorized activity before data exfiltration occurs—remains a critical hurdle. For consumers, the nature of this breach suggests that the threat extends beyond simple login credentials to include immutable identifiers like Social Security numbers and medical history, which carry long-term risks for identity theft and fraud.
Sources
- SecurityWeek Original source
- filed Also reporting
- notification Also reporting
Continue Reading
Healthcare SSO Targeted by ShinyHunters
A new advisory from Health-ISAC warns that extortion actors are compromising single-sign-on credentials to exfiltrate cloud data.
Steam Forums Hit by ClickFix Malware
Threat actors are exploiting technical support discussions on Steam to trick gamers into executing malicious PowerShell cryptominers.
The Mystery of Hacktivist Phineas Fisher
A decade after their most prominent breaches, the figure known as Phineas Fisher remains one of cybersecurity's enduring enigmas.