Эрүүл мэндийн мэдээллийн үйлчилгээ үзүүлэгч CareCloud компани өөрийн үүлэн орчинд хадгалагдаж байсан сая сая үйлчлүүлэгчийн эмнэлгийн болон хувийн мэдээлэл хакеруудын гарт орсныг албан ёсоор баталлаа.
Нью-Жерси мужид төвтэй тус технологийн компани нь АНУ-ын олон арван мянган эрүүл мэндийн байгууллагад цахим эмнэлгийн бүртгэлийн үйлчилгээ үзүүлдэг. Гуравдугаар сард гарсан энэхүү кибер халдлагын үеэр хакерууд Amazon Web Services платформ дээр байршуулсан өгөгдлүүд рүү нэвтэрч, зургаан өдрийн турш мэдээлэл олзлон авсныг компани тогтоожээ.
Халдлагад өртсөн 3.75 сая орчим хүний овог нэр, шуудангийн хаяг, нийгмийн даатгалын дугаар, эмнэлгийн болон эрүүл мэндийн түүх алдагдсан байна. Түүнчлэн паспорт, жолооны үнэмлэх зэрэг төрийн байгууллагаас олгосон үнэмлэхний дугаар болон банк санхүүгийн мэдээлэл хакеруудын гарт орсон нь эрсдэлийг улам нэмэгдүүлж байна.
CareCloud-ийн гүйцэтгэх захирал Стивен Снайдер уг ноцтой зөрчлийн талаар олон нийтэд дэлгэрэнгүй тайлбар өгөөгүй байгаа бөгөөд хакеруудад төлбөр төлсөн эсэх болон кибер аюулгүй байдлын хариуцлагатай холбоотой асуултуудад хариу өгөхөөс татгалзжээ. АНУ-ын Эрүүл мэнд, хүний үйлчилгээний яамны (HHS) мэдээллээр, энэхүү үйл явдал нь 2026 онд бүртгэгдсэн эрүүл мэндийн салбарын хамгийн том таван кибер халдлагын нэг болж байна.
Энэ онд эрүүл мэндийн салбарт томоохон хэмжээний мэдээллийн зөрчлүүд ар араасаа гарсаар байгаа бөгөөд тухайлбал, DentaQuest компанийн мэдээллийн санд халдсаны улмаас 15 сая хүний хувийн мэдээлэл алдагдсан тохиолдол бүртгэгдээд байна. Мөн TriZetto болон Craneware зэрэг компаниуд энэ онд хакеруудын халдлагад өртөж, олон сая үйлчлүүлэгчийнхээ мэдээллийг алдсан нь салбарын кибер аюулгүй байдлын эмзэг байдлыг дахин харуулж байна.
Дэлгэрэнгүйг эх сурвалжаас харах
↓Эх сурвалжийг нээх ↓
Hackers have stolen the personal information and medical records of more than 3.75 million people in a data breach at health data giant CareCloud, the company has confirmed with federal regulators. The disclosure marks the first confirmation of the scale of the data breach, which is now confirmed to be the fifth-largest theft of health data in 2026 so far.
CareCloud detailed the March data breach in a filing with the Department of Health and Human Services (HHS) on Monday. The number of affected victims was reportedly revised up in an update on Tuesday, though it’s unclear if the figure is expected to rise further.
The New Jersey-based tech company provides electronic medical record storage to tens of thousands of healthcare providers around the United States, consequently serving millions of patients. CareCloud handles a large amount of patient data and billing information on behalf of hospitals, doctor’s offices, and other medical practices.
CareCloud has not publicly commented on the cyberattack since it disclosed the breach in March, when it said hackers had accessed patients’ medical data stored in one of its cloud storage environments over six days. The company later said in data breach notifications that the hackers exfiltrated data from the company’s Amazon Web Services account and stole reams of patient data.
The stolen data includes patients’ names, postal addresses, Social Security numbers, and their medical and health information. The hackers also took government-issued identification numbers, such as passports and driver’s licenses, as well as banking and financial information.
CareCloud chief executive Stephen Snyder has not responded to multiple emails to date requesting information about the incident, including whether the company has paid the hackers; who, if anyone, is responsible for cybersecurity at the company; or if Snyder plans to resign following the incident.
The breach at CareCloud follows several sizable healthcare breaches confirmed this year.
Tech giant TriZetto confirmed in March that a 2024 data breach affected 3.4 million people’s data, and an as-yet-unspecified number of people have had their data stolen during a July data breach at healthtech billing software maker Craneware.
According to HHS’ running tally of healthcare data breaches, dental insurance giant DentaQuest has had the largest data breach this year so far, with at least 15 million people’s personal and health information being affected.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

