
CARECLOUD has begun notifying more than 350 000 patients that their personal and medical information was exposed after attackers infiltrated a compromised AWS environment used by the company’s electronic health record platform.
The disclosure came after the Massachusetts Office of Consumer Affairs and Business Regulation received a breach notice filed by the vendor on 31 July 2026.
The incident highlights the growing risk that cloud‑based health‑IT services pose to patient privacy when security controls lapse.
According to the investigation, the unauthorized access occurred between 10 March and 16 March 2026, when attackers leveraged a misconfigured IAM role to move from an initial foothold into the broader AWS tenant.
Once inside, they enumerated S3 buckets and EC2 instances that stored backup copies of the electronic health record database.
Data was exfiltrated over several hours using encrypted channels that blended with normal traffic, making detection difficult.
No malware was installed on victim endpoints; the breach was purely a cloud‑misconfiguration issue.
The stolen data set includes full names, residential addresses, dates of birth, Social Security numbers, health insurance policy numbers and portions of patients’ medical histories such as diagnoses and prescribed medications.
Financial details like bank account numbers and payment card information were also present in some of the exported files.
This combination of identifiers gives attackers the material needed to craft convincing phishing campaigns or to file fraudulent tax returns.
CareCloud has stated that, as of the notice date, there is no evidence that the stolen information has been misused.
Regulators in Massachusetts were notified on the same day the vendor issued its public statement, and the breach has been added to the state’s database of reported incidents.
CareCloud is offering affected individuals up to twenty‑four months of free identity theft protection, which includes credit monitoring and fraud resolution services.
The company has engaged a third‑party forensic firm to review its cloud configuration and to recommend hardening steps.
No ransom note or extortion demand has been discovered in the artefacts collected during the investigation.
Individuals who receive a notice should consider placing a fraud alert or a credit freeze with the major credit bureaus to prevent new accounts from being opened in their name.
They should also review explanation of benefits statements and insurance claims for any unfamiliar activity.
Phishing attempts that reference the breach or offer fake credit‑monitoring enrolment are likely to increase, so recipients must verify any unexpected email or telephone request before divulging personal data.
Using the complimentary identity theft service can help detect early signs of misuse, but vigilance remains essential.
Organisations that run workloads in AWS should enforce