A major cybersecurity breach at CareCloud, a healthcare technology company, has compromised the personal and medical information of more than 3.75 million people across the United States.
The company provides electronic health record management systems to tens of thousands of healthcare providers, meaning even individuals who never opened an account with CareCloud directly may find themselves among the victims.
The intrusion occurred in March when an unauthorized party gained access to the company's cloud services environment and maintained that access for approximately six days. According to CareCloud, the attacker claimed to have stolen data from its databases, though the company stated it found no evidence of continued unauthorized activity after the breach was contained. Initial estimates placed the number of affected individuals in the hundreds of thousands, but that figure later surged to more than 3.75 million.
The compromised information varies by individual and may include names, addresses, Social Security numbers, medical information, driver's license and passport details, as well as banking and financial data.
Following discovery of the incident, CareCloud said it brought in external cybersecurity experts, notified authorities, and secured the affected environment. The company is also offering complimentary identity theft protection services to those impacted.







