CareCloud disclosed a breach affecting 345,000 people after hackers stole medical and financial data from its AWS-hosted systems.TechCrunch reports that CareCloud, the New Jersey-based health tech company that stores patient records for more than 45,000 providers across the US, is finally notifying people impacted by a breach the firm first disclosed back in March. New disclosures put the number affected so far at nearly 350,000, and that number is still climbing as more states get their filings.CareCloud is a U.S. healthcare technology company that provides cloud-based electronic health records (EHR), medical practice management, revenue cycle management, billing, and AI-powered software for hospitals and medical practices. It employs approximately 3,650 people, and reported $120.5 million in revenue and $10.8 million in GAAP net income for fiscal year 2025. CareCloud handles the kind of data that makes a breach genuinely dangerous rather than just annoying. Doctors’ offices, hospitals, and medical practices around the country feed patient records into its systems, which means a hit on CareCloud is really a hit on everyone those providers see. The company stayed mostly quiet for four months after its initial admission, and it took a batch of state filings to fill in the actual details.According to a data breach notice filed with California’s attorney general’s office this week, threat actors had access to one of CareCloud’s electronic health record data stores for at least six days, from March 10 to March 16. “The investigation determined that, between March 10 and March 16, 2026, an unauthorized third party accessed one of CareCloud’s AWS environments and claimed to have exfiltrated data from databases within that environment.” reads the data breach notice. “There is no evidence of unauthorized activity within CareCloud’s environment since March 16, 2026.”The notice states that an attacker “claimed to have exfiltrated data from databases.” CareCloud hasn’t provided technical details about the security breach.At this time, nobody has publicly claimed responsibility for the attack. What the filings do confirm is the technical detail TechCrunch had already reported back in March: the attackers broke into data storage that CareCloud hosted on Amazon Web Services.Compromised info may include names, home addresses, and Social Security numbers, along with government ID numbers like passports and driver’s licenses. Bank account details and payment card numbers were exposed too, on top of a substantial amount of medical and health information, the exact combination identity thieves and health insurance fraudsters both want.In March, Cognizant’s TriZetto Provider Solutions disclosed a breach affecting 3.4 million people, and just last week, billing software provider Craneware confirmed hackers stole a significant volume of data belonging to its hospital and pharmacy clients.These incidents demonstrate how healthcare data keeps ending up in the wrong hands, and the public usually finds out well after the fact. If there’s a silver lining here, it’s that California’s disclosure rules are the reason we know any of this at all this soon. Without a state forcing the paperwork, “we’ll notify affected patients eventually” would probably still be the entire update.Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, newsletter)