NJ-based Medical Software Company Breach Impacts ~350K

NJ-based CareCloud, which provides cloud-based EHR, billing, and revenue cycle software to more than 45,000 U.S. healthcare providers, has begun notifying nearly 350,000 people affected by a March 2026 data breach. According to a notice filed with California's attorney general, attackers accessed one of CareCloud's AWS environments between March 10 and March 16 and claimed to have exfiltrated data from databases. Exposed information may include names, addresses, SSNs, IDs, bank and payment card details, and extensive medical and health data. CareCloud stayed largely silent for four months until state filings forced disclosure. No group has publicly claimed responsibility.

The case continues a striking pattern in healthcare tech: Cognizant's TriZetto disclosed a 3.4 million-person breach in March, Craneware confirmed a significant theft last week, and MCBS recently disclosed a 1.26 million-patient breach with 3.3 TB now publicly downloadable. In every case, the target is a vendor sitting between providers and patients, holding the exact combination of PHI and financial data attackers monetize most easily. In CareCloud's case, six days of unauthorized access to an AWS-hosted data store was enough to expose hundreds of thousands of records — a reminder that cloud environments require the same depth of monitoring as on-premises systems, and often get less.

Cloud-hosted healthcare platforms need visibility that treats AWS, Azure, and other public cloud environments as first-class targets — with continuous baselining of access and data egress, plus full-fidelity evidence to answer the questions that arrive months later. When investigators can query a single indexed record of exactly what happened during the intrusion window, for example, in a platform like NIKSUN, the 4-month gap between initial disclosure and patient notification shrinks dramatically, and vendors can meet state and federal notification obligations with specifics rather than placeholders. Read more about this story on our LinkedIn page

We use cookies to offer you a better browsing experience and to analyze site traffic. By using our site, you consent to our use of cookies.

Essential Cookies
Site Analytics