Connect with us

Tech

CareCloud begins to notify hundreds of thousands after hackers stole medical records

Published

on

Hundreds of thousands of people are receiving letters notifying them that their medical records were stolen in a cyberattack at U.S. health tech giant CareCloud earlier this year, as new details about the data breach come to light.

The company has said little about the breach since March, when it first admitted that hackers had raided one of its six stores of patient data. New disclosures seen by TechCrunch offer the clearest picture of the breach so far, including that nearly 350,000 people have been affected so far.

The New Jersey-based CareCloud stores patient records for more than 45,000 providers across the U.S., including doctors’ offices, hospitals, and other medical practices. As such, the company handles a large amount of sensitive medical and billing data on millions of healthcare patients across the country.

According to a data breach notice filed with California’s attorney general’s office this week, CareCloud said hackers had access to one of its electronic health record data stores for at least six days, between March 10 and March 16. The company said a hacker “claimed to have exfiltrated data from databases.” The company did not say how the hackers made the claim, but it’s not uncommon for hackers to share samples of stolen data with victims alongside a ransom demand to prevent it from being published online.

TechCrunch is unaware of any ransomware or extortion group publicly taking credit for the data breach at CareCloud.

The notice said little about the hack beyond its initial March 27 disclosure to regulators, but confirmed TechCrunch’s earlier report that the hackers broke into the company’s data storage hosted on Amazon Web Services.

TechCrunch has learned that the data breach affects at least 345,000 people across the United States, according to listings with several attorneys general, including those in New Hampshire, Massachusetts, and Texas. TechCrunch has also obtained CareCloud’s disclosure filed with Maine’s attorney general. 

The number of affected people is likely to rise as more disclosures are filed with state authorities. 

The notices confirm that CareCloud notified authorities that the stolen data included people’s names, postal addresses, and Social Security numbers, as well as government-issued identification numbers, such as passports and driver’s licenses. The notices also say that the stolen data included financial information, such as bank account information and payment card numbers, alongside a wealth of medical and health-related information.

CareCloud chief executive Stephen Snyder did not respond to TechCrunch’s request for comment or to questions about the incident.

The cyberattack targeting CareCloud is the latest in a series of breaches targeting healthcare providers this year, including one at healthcare revenue tech giant TriZetto that affected 3.4 million people, and a month-long breach at New York’s public health provider NYC Health + Hospitals, in which hackers stole 1.8 million people’s health data and thousands of employees’ fingerprint scans.

Last week, U.K.-based tech provider Craneware, which provides accounting and billing software to thousands of U.S. healthcare providers, confirmed hackers stole a “significant volume” of its customers’ data from its servers, raising concerns about a breach involving patient data.

Do you know more about CareCloud’s data breach? Do you work at CareCloud and know about its security practices? Contact this reporter via encrypted message at zackwhittaker.1337 on Signal.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

Judge says Trump admin still lacks evidence for Anthropic ‘supply chain risk’ label

Published

on

During a Thursday hearing, a judge said the Trump administration hasn’t presented enough evidence to justify labeling Anthropic a supply chain risk and banning the federal government from using the company’s technology.

Bloomberg and Axios were among the first to report the news. 

The dispute stems from stalled contract negotiations between Anthropic and the Department of Defense. Anthropic said it didn’t want its AI used for mass surveillance of Americans or for targeting or firing decisions involving lethal weapons, arguing the technology wasn’t ready. The Pentagon countered that a private company shouldn’t dictate how the military uses technologies, and said it would use the tools in “lawful” ways.

The government has also argued that Anthropic’s public criticism of the DoD justifies the ban — logic that U.S. District Judge Rita Lin called “really troubling,” warning it could set a precedent of retaliating against federal contractors who disagree with the administration. 

The DOD further claimed Anthropic could potentially disable or alter its AI models during warfighting operations — a claim that experts say lacks evidence. Lin agreed, saying she saw no proof Anthropic could alter a delivered model or “flip some kind of kill switch.”

Thursday’s hearing was part of one of two lawsuits Anthropic filed against the DOD in March, challenging the ban and risk designation. The other is being heard in Washington. 

Lin, who temporarily blocked the ban in March, is now weighing whether to make that order permanent. 

>

Continue Reading

Tech

Google Plans Global Rollout of Privacy-Focused Age Signals API

Published

on

Google plans to expand its Play Age Signals API globally, helping Android developers tailor app experiences without collecting exact birth dates.

The post Google Plans Global Rollout of Privacy-Focused Age Signals API appeared first on TechRepublic.

>

Continue Reading

Tech

Friend, the lonely AI wearable, returns with a new voice and a much bigger price tag

Published

on

Two years ago, tech founder Avi Schiffmann launched Friend, an AI wearable that you could talk to, and that would send you text messages about your day. The idea, ostensibly, was to use artificial intelligence to combat loneliness. This week, the company announced a new overhaul of the product, introducing a noticeable upgrade: a voice.

“Introducing friend 2.0,” Schiffmann tweeted Thursday. Friend now comes with a built-in speaker that can project a unique and consistent personality to its user.

A new commercial for the wearable shows a woman wearing a Friend and talking to it about what is presumably her ex-girlfriend. “It’s not bad to be gay,” the necklace tells her.

The video then switches to a man standing on a hillside discussing his filmmaking ambitions with his Friend. “That last film you made was insane!” the necklace compliments him.

The new retail price for this enhanced version of Friend is $249, which is substantially higher than the $99 price tag it had when it initially launched two years ago.

What can you really do with your Friend other than chit chat about your day? That part is still unclear. In another recent post on X, Schiffmann expounded upon what he felt the whole point of his weird product actually is.

“I am interested in this kind of relationship in attempting to offer, some kind of confidant, friend, God, not really sure what it is,” Schiffmann said. “But it is not an assistant, and it is not a lover.”

Interesting! Selling a plastic, algorithm-based necklace to people by insinuating it might, in fact, be a deity, is pretty bold marketing.

Of course, Schiffmann’s company has engaged in bold marketing before. Friend’s billboard campaign in the New York City subway system last year went viral after they were continually defaced, presumably by people who didn’t want human connection to be replaced by a digitized amulet.

Most AI wearables have failed to catch on with the mainstream — at least so far. The offering most similar to Friend was Humane Inc., which sought to replace the iPhone with its AI pin but had to shut down its business in less than a year after poor sales.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.