CareCloud is telling hundreds of thousands of patients that hackers stole their medical records.
The health tech data giant, which stores vast troves of patient medical information for providers, confirmed it is notifying people whose records were compromised. The company said hackers broke into one of its protected health data stores. CareCloud has not disclosed how the intrusion happened or how long the attackers had access. The notifications are going out now, according to the company.
Medical records are worth more to criminals than credit card numbers because they cannot be canceled and reissued. A breach at a company that aggregates data across many providers means the blast radius extends well beyond CareCloud's own users. That is the recurring problem with health data platforms: consolidation makes breaches rarer to report but far larger when they happen.
Expect the usual playbook: free credit monitoring, a terse statement, and no real accountability for the industry's habit of centralizing exactly the data that should be hardest to steal.