CareCloud Breach Exposes 3.7 Million Patient Records in AWS Hack
Healthcare technology provider CareCloud has disclosed a major data breach impacting 3,756,469 individuals, according to filings with the U.S. Department of Health and Human Services. The company, which serves more than 45,000 healthcare providers across the United States, confirmed that an unauthorized actor gained access to one of its Amazon Web Services (AWS) environments between March 10 and March 16, spending approximately eight hours inside the system before exfiltrating sensitive data. The compromised environment housed electronic health records for hospitals and medical practices nationwide.
The stolen dataset is extensive and highly sensitive. CareCloud's breach notification letters revealed that attackers obtained Social Security numbers, government ID numbers, credit and debit card information, medical records, and health insurance details. Affected individuals can use our email breach checker to verify whether their credentials appeared in this or prior exposures. State-level filings indicate that more than 270,000 residents in Texas, nearly 58,000 in Oregon, and 23,000 in South Carolina were impacted, with New Hampshire, Massachusetts, and California declining to disclose specific counts. Given the exposure of financial and medical identifiers, impacted users should also run their credentials through our password checker and rotate any reused passwords immediately.
CareCloud reported the intrusion to law enforcement on the same day it was detected, and by March 24 escalated the disclosure to the Securities and Exchange Commission, citing "the sensitivity of the potentially affected information and the potential consequences of the incident." The company generated $120.5 million in revenue in its last fiscal year, underscoring the scale of the breach relative to the organization's footprint. No ransomware group or threat actor has publicly claimed responsibility for the intrusion as of publication. CareCloud joins a growing list of electronic health record vendors targeted in 2024 and 2025, including an incident involving a vendor serving more than 2,000 U.S. hospitals.
The incident highlights persistent risks associated with cloud-hosted healthcare data. Misconfigured AWS environments and over-privileged access controls remain common entry points for adversaries targeting the sector. Organizations operating in regulated industries like healthcare should audit their cloud posture regularly and run an privacy checkup to identify exposed assets, while security teams can use our SSL/TLS checker to validate certificate integrity across cloud endpoints. With no group claiming the attack and patient SSNs circulating in criminal forums, the long-tail consequences of this breach will likely continue for months.