Business / news
CareCloud Begins Notifying Patients After Medical Records Breach
CareCloud has started sending letters to hundreds of thousands of patients whose medical records were stolen in a cyberattack earlier this year, with new details revealing nearly 350,000 people affected.
Health technology firm CareCloud has begun notifying hundreds of thousands of patients that their medical records were compromised in a data breach earlier this year. The New Jersey-based company filed a notice with California's attorney general's office this week, offering the clearest picture yet of the incident.
According to the filing, hackers accessed one of CareCloud's electronic health record data stores for at least six days, between March 10 and March 16. The company said a hacker claimed to have exfiltrated data from its databases.
Nearly 350,000 people have been affected so far. CareCloud stores patient records for more than 45,000 healthcare providers across the United States, including doctors' offices, hospitals, and other medical practices, meaning the breach touches a large volume of sensitive medical and billing information.
The company first admitted to the breach in March but had disclosed few details until now. No ransomware or extortion group has publicly taken credit for the attack.