Eight hours of access, 3.7 million records
CareCloud has notified 3,756,469 people. The intruder was inside one AWS environment for about eight hours in March.
2 minEnterprise CyberSec
CareCloud, an electronic health record provider serving more than 45,000 clinicians on $120.5 million of annual revenue, has notified 3,756,469 people of a breach. The exposed set covers personal details, social security numbers, identity document numbers, credit and debit card information, medical records and insurance data.
The access window was narrow. An intruder was inside a single AWS environment between 10 and 16 March, for approximately eight hours. The company notified the Securities and Exchange Commission on 24 March, citing the sensitivity of the material and the possible consequences.
Two numbers that do not sit together comfortably
Eight hours produced 3.7 million records. That ratio says more about how the data was stored than about how the attacker worked: a set that size leaves in eight hours only if it is available as a set. Notified counts published so far include over 270,000 in Texas, 23,000 in South Carolina and nearly 58,000 in Oregon.
The other gap is the calendar. The SEC was told in March; individual notifications and the full count arrived in August. Five months separate the regulator learning and the affected people learning.
No group has claimed responsibility. For a set combining social security numbers, payment cards and medical records, silence is not reassurance — it is the profile of data that sells privately rather than being advertised.
Retold from The Record. This is a summary in our own words; follow the link for the original reporting.