Hundreds of thousands of people are now receiving letters tied to the CareCloud data breach, following disclosures that expand what is known about the incident. The notifications arrive after CareCloud disclosed the issue to regulators in March, with later filings providing a clearer picture of how long attackers may have had access and what types of data were involved.
While CareCloud has previously shared only limited details, new information reviewed from notices submitted to state authorities indicates the breach impacted at least several hundred thousand individuals across the United States. As additional disclosures are filed, that number could continue to grow.
What CareCloud said early on
In March, CareCloud acknowledged that hackers accessed one of its patient-data locations. The company disclosed the incident to regulators but did not provide extensive technical detail at the time. According to later reporting, the first disclosure covered the fact that an attacker had raided one of multiple stores of patient information.
CareCloud is based in New Jersey and supports healthcare providers nationwide by storing patient records. The company is tied to data covering millions of patients, largely through the records it maintains for tens of thousands of providers across the U.S., including hospitals and doctors’ offices.
How long hackers may have accessed data
A notice filed with California’s attorney general reportedly states that hackers gained access to an electronic health record data store for at least six days. The timeframe cited in the notice runs from March 10 to March 16.
The filing also includes an attacker claim that data had been “exfiltrated” from the relevant databases. The notice does not explain how that claim was made or proven, but data-breach patterns in recent years include cases where attackers share samples of stolen information with victims while attempting to prevent publication or negotiate payment.
Tech reporting does not indicate that a ransomware or extortion group has publicly taken responsibility for the incident. However, filings with multiple attorneys general reinforce that the breach involved sensitive patient and financial data.
Where the breach occurred: data hosted on AWS
Additional disclosures align with earlier reporting that the attackers broke into CareCloud’s data storage environment hosted on Amazon Web Services. That detail matters because it helps frame the incident as a compromise involving cloud-hosted storage rather than an internal breach alone.
In practical terms, access to a hosted data store can enable attackers to view, copy, or export records if security controls fail or if credentials are obtained. The disclosures reviewed focus on the fact that the breach targeted the storage used for electronic health records.
How many people were affected so far
By the time of the later disclosures, the number of individuals potentially impacted is substantial. Reporting based on listings with several attorneys general suggests the breach affects at least 345,000 people across the United States.
Because the notifications and filings are still continuing across states, the affected population is expected to rise as more agencies receive additional breach documentation.
What types of data were included
The notices describe multiple categories of information, including both identity data and health-related information. According to the disclosures tied to the breach, the stolen information includes:
- Names
- Postal addresses
- Social Security numbers
- Government-issued identification numbers such as passport and driver’s license numbers
- Financial information including bank account details and payment card numbers
Beyond that, the filings indicate the breach involved a wide range of medical and health-related details. For affected individuals, this combination can increase risk, because identity theft, fraud, and targeted social engineering attempts can become more effective when personal and medical context are exposed together.
Why more notifications may still arrive
Many cyber incidents begin with a first regulator disclosure, but later stages can involve additional notices filed as investigators confirm the scope of the compromise. In this case, reporting indicates that the total number of affected people is likely to increase as further notices are submitted to state authorities.
That’s one reason affected individuals may receive letters at different times. States may require separate filings, and each filing can update the number of impacted residents once an organization confirms which data elements were involved and which systems were accessed.
CareCloud’s role in U.S. healthcare data
CareCloud stores patient records for a large network of providers, which helps explain why the impact of a breach can scale quickly. When healthcare data is aggregated across many clinics, hospitals, and medical practices, attackers can potentially reach a broad set of individuals even if the compromise occurs in a single central environment.
The company’s infrastructure supports billing and records operations for providers nationwide. That means the breach is not limited to “medical history” in a narrow sense; it may also include data tied to financial processes and identification details.
Not the only healthcare breach this year
The CareCloud incident is part of a wider pattern of healthcare-related security events reported in the same year. Other healthcare data breaches referenced in reporting include an incident involving a revenue technology provider that affected millions of people, as well as a month-long intrusion affecting a New York public health provider where attackers reportedly stole health data and employee biometric information.
Separately, a U.K.-based tech provider serving healthcare accounting and billing functions reportedly confirmed that hackers stole a significant volume of customer data. Taken together, these cases reinforce that attackers continue to target healthcare organizations due to the sensitivity and value of the data they hold.
What we know about response and communication
In the reporting reviewed, CareCloud’s chief executive Stephen Snyder did not respond to requests for comment regarding the incident. As with many breaches, official updates may continue to lag behind regulator notices because investigations, legal obligations, and data-confirmation steps can take time.
For affected individuals, the most immediate practical information often comes from the letters themselves, which can outline what happened in broad terms and what steps individuals may consider next. Those steps commonly include monitoring financial accounts, watching for suspicious activity, and reviewing credit or identity protection options.
How affected people can prepare
If you receive a notice tied to the CareCloud data breach, take it seriously. Even when a letter provides limited technical detail, the disclosed data types—especially Social Security numbers, addresses, and financial information—can be useful to criminals attempting identity fraud.
Consider acting promptly: verify whether the contact information in the letter matches what you expect from the organization, review credit and bank statements more closely than usual, and be cautious of phishing messages that reference healthcare, billing, or account verification. If your information is exposed, attackers may try to “bridge” the gap between the breach and a new scam by pretending to be from a clinic, insurer, or payment service.
Bottom line
The latest disclosures around the CareCloud data breach indicate a breach affecting at least hundreds of thousands of people, with hackers reportedly accessing an electronic health record data store for at least six days in March. The notices describe sensitive personal data, government identification numbers, and financial details alongside medical information.
As additional filings continue across states, the number of affected individuals may rise, and affected people should remain alert for identity and financial risks tied to the exposure.
