CareCloud begins to notify hundreds of thousands after hackers stole medical records

CareCloud begins to notify hundreds of thousands after hackers stole medical records

CareCloud 开始通知数十万受害者:医疗记录遭黑客窃取

Hundreds of thousands of people are receiving letters notifying them that their medical records were stolen in a cyberattack at U.S. health tech giant CareCloud earlier this year, as new details about the data breach come to light. The company has said little about the breach since March, when it first admitted that hackers had raided one of its six stores of patient data. 随着数据泄露事件的更多细节浮出水面,数十万人正在收到通知信,告知他们的医疗记录在今年早些时候美国医疗科技巨头 CareCloud 遭受的网络攻击中被窃取。自 3 月份首次承认黑客入侵了其六个患者数据库之一以来,该公司对此次泄露事件一直鲜有披露。

New disclosures seen by TechCrunch offer the clearest picture of the breach so far, including that nearly 350,000 people have been affected so far. The New Jersey-based CareCloud stores patient records for more than 45,000 providers across the U.S., including doctors’ offices, hospitals, and other medical practices. As such, the company handles a large amount of sensitive medical and billing data on millions of healthcare patients across the country. TechCrunch 获得的新披露信息提供了迄今为止关于此次泄露事件最清晰的图景,其中包括目前已有近 35 万人受到影响。总部位于新泽西州的 CareCloud 为全美 4.5 万多家医疗服务提供商(包括医生诊所、医院和其他医疗机构)存储患者记录。因此,该公司处理着全国数百万医疗患者的大量敏感医疗和账单数据。

According to a data breach notice filed with California’s attorney general’s office this week, CareCloud said hackers had access to one of its electronic health record data stores for at least six days, between March 10 and March 16. The company said a hacker “claimed to have exfiltrated data from databases.” The company did not say how the hackers made the claim, but it’s not uncommon for hackers to share samples of stolen data with victims alongside a ransom demand to prevent it from being published online. 根据本周向加州总检察长办公室提交的数据泄露通知,CareCloud 表示,黑客在 3 月 10 日至 3 月 16 日期间,至少有六天时间可以访问其电子健康记录数据库之一。该公司称,一名黑客“声称已从数据库中窃取了数据”。公司并未说明黑客是如何提出这一主张的,但黑客在提出勒索要求时向受害者分享部分被盗数据样本,以威胁受害者防止数据被发布到网上,这种情况并不罕见。

TechCrunch is unaware of any ransomware or extortion group publicly taking credit for the data breach at CareCloud. The notice said little about the hack beyond its initial March 27 disclosure to regulators, but confirmed TechCrunch’s earlier report that the hackers broke into the company’s data storage hosted on Amazon Web Services. 目前,TechCrunch 尚未获悉有任何勒索软件或敲诈勒索组织公开承认对 CareCloud 的数据泄露事件负责。除了 3 月 27 日向监管机构提交的初步披露外,该通知对黑客攻击的细节披露甚少,但证实了 TechCrunch 此前的报道,即黑客入侵了该公司托管在亚马逊云科技(AWS)上的数据存储系统。

TechCrunch has learned that the data breach affects at least 345,000 people across the United States, according to listings with several attorneys general, including those in New Hampshire, Massachusetts, and Texas. TechCrunch has also obtained CareCloud’s disclosure filed with Maine’s attorney general. The number of affected people is likely to rise as more disclosures are filed with state authorities. TechCrunch 获悉,根据新罕布什尔州、马萨诸塞州和德克萨斯州等多位总检察长办公室的备案信息,此次数据泄露事件影响了全美至少 34.5 万人。TechCrunch 还获得了 CareCloud 向缅因州总检察长提交的披露文件。随着更多披露信息提交给州政府部门,受影响人数可能会进一步上升。

The notices confirm that CareCloud notified authorities that the stolen data included people’s names, postal addresses, and Social Security numbers, as well as government-issued identification numbers, such as passports and driver’s licenses. The notices also say that the stolen data included financial information, such as bank account information and payment card numbers, alongside a wealth of medical and health-related information. 通知证实,CareCloud 已告知当局,被盗数据包括个人的姓名、邮寄地址、社会安全号码,以及政府签发的身份证件号码(如护照和驾照)。通知还指出,被盗数据除了包含大量医疗和健康相关信息外,还包括银行账户信息和支付卡号等财务信息。

CareCloud chief executive Stephen Snyder did not respond to TechCrunch’s request for comment or to questions about the incident. CareCloud 首席执行官 Stephen Snyder 未回应 TechCrunch 的置评请求,也未回答有关此次事件的问题。

The cyberattack targeting CareCloud is the latest in a series of breaches targeting healthcare providers this year, including one at healthcare revenue tech giant TriZetto that affected 3.4 million people, and a month-long breach at New York’s public health provider NYC Health + Hospitals, in which hackers stole 1.8 million people’s health data and thousands of employees’ fingerprint scans. 针对 CareCloud 的网络攻击是今年针对医疗服务提供商的一系列泄露事件中的最新一起。此前,医疗收入科技巨头 TriZetto 发生的数据泄露事件影响了 340 万人;纽约公共医疗服务机构 NYC Health + Hospitals 经历了一个月的泄露事件,黑客窃取了 180 万人的健康数据以及数千名员工的指纹扫描信息。

Last week, U.K.-based tech provider Craneware, which provides accounting and billing software to thousands of U.S. healthcare providers, confirmed hackers stole a “significant volume” of its customers’ data from its servers, raising concerns about a breach involving patient data. 上周,总部位于英国的科技供应商 Craneware(为数千家美国医疗服务提供商提供会计和计费软件)证实,黑客从其服务器中窃取了“大量”客户数据,引发了人们对涉及患者数据泄露的担忧。