The data breach at cloud-based healthcare provider CareCloud now affects more than 3.7 million individuals, a tenfold increase from the roughly 350,000 initially reported, according to the Department of Health and Human Services breach tracker.
CareCloud disclosed in early July that it had detected a network intrusion in mid-March, discovered following a disruption to one of its electronic health record environments. An investigation revealed that threat actors gained access to one of the company’s AWS environments between March 10 and March 16, according to SecurityWeek.
Stolen Data Includes SSNs, Medical Records, and Payment Cards
The stolen information includes names, addresses, Social Security numbers, driver’s license numbers, dates of birth, health insurance information, and medical and healthcare records. For a limited subset of individuals, attackers also obtained full payment card data. No known cybercrime group has publicly claimed responsibility for the attack.
Data breach reports filed by state attorneys general in July initially showed tens of thousands of affected individuals per state, totaling roughly 350,000. However, the HHS healthcare data breach tracker updated its numbers this week, first to 3,371,508 and then to 3,756,469 affected individuals. The HHS confirmed to SecurityWeek that the figure is accurate and reflects the most recent data provided by the company.
Healthcare Breaches Continue to Escalate
The massive gap between the initial and revised figures has drawn scrutiny. SecurityWeek reported that the tenfold increase initially raised suspicion of a clerical error, but HHS confirmed the numbers are correct. CareCloud has not disclosed whether it paid a ransom to prevent stolen data from being published.
The breach is the latest in a series of large-scale healthcare data compromises this year. The healthcare sector remains one of the most targeted industries for ransomware and data theft, with attackers drawn by the high value of medical records and personal information on dark web markets. Industry analysts note that cloud environments have become an increasingly attractive target, as a single misconfiguration or compromised credential can expose data across multiple downstream clients.
CareCloud provides cloud-based revenue cycle management, telehealth, and electronic health record solutions to physician practices and healthcare organizations across the United States. The breadth of its services means the compromised AWS environment likely held data touching a wide network of medical practices and their patients.
Sources: SecurityWeek; HHS Office for Civil Rights breach tracker; SC Media
discussion