CareCloud says a March breach exposed personal data on 3.7 million patients - nearly five months after it happened.
CareCloud, a healthcare technology company that serves more than 40,000 providers across all 50 states, first told the SEC in March that a "temporary network disruption" had knocked one of its electronic health record systems offline for about eight hours. That filing did not mention a breach. In late July, the company began notifying customers that unidentified attackers had accessed one of its AWS environments and stolen files from it, though it has only confirmed that people's full names were taken. A separate filing with the Department of Health and Human Services set the final toll at 3,756,469 people, and no hacking group has claimed responsibility.
CareCloud told the SEC the incident was not material, even though it now says 3.7 million patient records were exposed. The company still has not said what data, beyond names, attackers actually got hold of, or whether it was merely exposed or exfiltrated.
For the millions of people affected, that's the real gap: not the months between breach and notice, but the fact that "personal records" at a health records company could mean almost anything, and CareCloud still hasn't specified what.