Health

CareCloud breach exposed patient data, including Social Security numbers

Hackers accessed one of CareCloud’s six EHR systems for eight hours, exposing names, birth dates, Social Security numbers and medical records.

Marcus Williams··2 min read
Published
Listen to this article0:00 min
Share this article:
CareCloud breach exposed patient data, including Social Security numbers
Source: pexels.com

CareCloud said hackers accessed one of its six electronic health record environments for about eight hours on March 16, exposing names, dates of birth, Social Security numbers, health insurance information and medical information. The New Jersey-based health technology firm, which serves more than 45,000 providers across all 50 states, disclosed the incident in a March 24 SEC filing.

CareCloud said the intrusion caused an isolated network disruption and that it fully restored the affected environment the same evening. A Massachusetts Attorney General notice later said CareCloud determined on June 24 that protected health information had been affected, and that notice letters were being sent to affected individuals.

AI-generated illustration
AI-generated illustration

The mix of data tied to the breach carries immediate fallout for patients. Social Security numbers can be used for identity theft and tax fraud, while dates of birth, insurance details and medical information can help criminals open accounts, submit fake claims or misuse health records in ways that are harder for patients to detect. Because the exposed data included both financial identifiers and health information, the breach touches both privacy and billing risk.

The timeline also underscores the pressure on health-tech vendors that hold records for clinics and hospitals. CareCloud’s environment was restored on March 16, but the company did not determine until June 24 that protected health information had been affected, leaving a long gap between the intrusion and the formal patient-impact determination. For vendors that operate core systems used by medical practices nationwide, that lag can complicate compliance with breach-notification rules and increase exposure to litigation.

Legal scrutiny followed quickly. On March 31, Edelson Lechtzin LLP announced it was investigating the CareCloud incident as a potential class action, and other breach-law firms also began publicizing reviews of the case. The attention reflects the broader risk created when third-party electronic health record systems are compromised, since one breach can put many providers and patients in jeopardy at once.

CareCloud’s footprint makes that risk national. Based in Somerset, New Jersey, the company supports providers in every state, which means any failure to secure a core EHR environment can ripple far beyond a single office or clinic.

This article was produced by Prism’s automated news system from verified source data, official records, and press releases, then run through automated quality and moderation checks before publishing. The system is built and supervised by the people who set the standards it runs under. Read our full AI policy.

Did this article answer your question?

Discussion

More in Health