Nearly 350,000 people are now learning that their most sensitive personal and medical information was stolen during a cyberattack on healthcare technology giant CareCloud earlier this year. Notifications arriving in mailboxes across the country this week provide the first detailed look at a breach the company disclosed in March but has since discussed only sparingly. Main Developments CareCloud began sending data breach notices to affected individuals after filing disclosures with state attorneys general in California, New Hampshire, Massachusetts, Texas, and Maine. The filings, reviewed by TechCrunch, confirm that at least 345,000 people have been impacted so far, a number expected to climb as additional states are notified. Hackers accessed one of CareCloud's electronic health record data stores for six days, from March 10 to March 16. The company stated that an unidentified hacker claimed to have exfiltrated data from its databases, though CareCloud did not specify how that claim was communicated—commonly, attackers share stolen samples alongside a ransom demand to pressure victims into paying. Read also: 4 Reasons Friend AI Wearable Returns With Voice and a $150 Price Hike No ransomware group has publicly taken credit for the attack, TechCrunch found. The breach was first acknowledged by CareCloud on March 27 in a brief regulatory filing that confirmed the intruders broke into data storage hosted on Amazon Web Services, matching TechCrunch's earlier reporting. The stolen data includes names, postal addresses, Social Security numbers, government-issued identification numbers such as passports and drivers licenses, financial account information, payment card numbers, and a broad range of medical and health-related records. CareCloud CEO Stephen Snyder did not respond to requests for comment. Background CareCloud, headquartered in New Jersey, stores patient records for more than 45,000 healthcare providers across the United States, including doctors offices, hospitals, and medical practices. This gives the company access to sensitive medical and billing data for millions of patients nationwide. The incident is the latest in a string of healthcare data breaches this year. In a separate attack, healthcare revenue technology firm TriZetto suffered a breach affecting 3.4 million people. New York City's public health provider NYC Health + Hospitals experienced a month-long intrusion that exposed 1.8 million patients' health data and thousands of employees' fingerprint scans. Just last week, Craneware, a U.K.-based tech provider supplying accounting and billing software to thousands of U.S. healthcare organizations, confirmed that hackers stole a significant volume of customer data from its servers, raising fresh concerns about patient data exposure across the sector. Why It Matters Healthcare data breaches carry uniquely severe consequences because the stolen information often includes immutable identifiers such as Social Security numbers and biometric data, which cannot be replaced like a credit card. Victims may face years of identity theft, medical fraud, and financial harm. For CareCloud, which serves tens of thousands of providers, the breach undermines trust in the third-party platforms that hospitals and clinics rely on to manage patient data. The incident also highlights the vulnerability of cloud-based healthcare systems, even when hosted by major providers like Amazon Web Services. What's Next The number of affected individuals is expected to rise as CareCloud files additional disclosures with state authorities. Affected patients will need to monitor their credit reports, medical bills, and explanations of benefits for signs of fraud. Regulatory investigations by state attorneys general and federal health authorities are likely, given the scale of the breach and the sensitivity of the data involved. CareCloud has not announced whether it will offer credit monitoring or identity theft protection services to those impacted.