Medical Records, SSNs, and Bank Details Exposed in CareCloud Data Breach Affecting 3.75 Million Individuals
What Happened — CareCloud, a provider of electronic health‑record and practice‑management SaaS, confirmed that an unauthorized actor accessed one of its Amazon Web Services environments from 10 to 16 March 2026. The intrusion disrupted an EHR environment for eight hours and, according to the company’s forensic analysis, resulted in the exfiltration of personal, medical, and financial data belonging to more than 3.75 million people.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a data‑exposure breach that SOC 2’s Confidentiality and Privacy principles are designed to prevent and document.
- Continuous evidence of cloud‑configuration controls, encryption at rest, and privileged‑access monitoring is essential to demonstrate due diligence during an audit.
- Verisq’s CookiePLUS capability can help map privacy‑law requirements (HIPAA, GDPR, CCPA) to SOC 2 controls and provide ready‑to‑use audit evidence.
Who Is Affected — Health‑care providers, clinics, and any organization that relies on CareCloud’s EHR platform; broadly, the HEALTH_LIFE industry and EHR‑service vendors.
Recommended Actions
- Verify that your own cloud‑environment configurations (IAM policies, network segmentation, logging) are continuously monitored and aligned with SOC 2 CC6.
- Review and update data‑retention, encryption, and access‑control policies; capture evidence in a centralized Trust Center.
- Conduct a privacy‑impact assessment and ensure DSAR processes are documented and testable.
Technical Notes — The attacker gained access to an AWS account, likely via compromised credentials or a mis‑configured role, and extracted data from multiple databases. Exfiltrated data includes full names, addresses, DOB, SSNs, driver’s‑license/passport numbers, medical records, health‑insurance details, and, for a subset, full credit‑card information (including CVV). Source: Malwarebytes Labs