CareCloud is mailing breach letters to at least 345,000 people whose Social Security numbers, driver’s license and passport numbers, bank details, and medical records sat exposed for six days on an Amazon Web Services database. That’s the number so far. It’ll climb as more states file.

I read the notice CareCloud filed with California’s DOJ this week. It confirms the hackers had access between March 10 and March 16, and that an attacker “claimed to have exfiltrated data from databases.” That’s the phrasing companies use when they haven’t verified a claim but can’t rule it out either. No ransomware crew has taken public credit, and CareCloud’s CEO Stephen Snyder hasn’t answered TechCrunch’s questions. Four months of silence between the March 27 initial disclosure and this week’s detailed notices is a long gap for a vendor sitting on 45,000 providers’ worth of patient data.

This is the third healthcare data vendor breach disclosed this year. TriZetto’s incident, filed with Maine’s AG and disclosed in TechCrunch’s March report, hit 3.4 million people and sat undetected for nearly a year before discovery. NYC Health + Hospitals lost 1.8 million records plus employee fingerprint scans. The pattern is back-office healthcare infrastructure, not hospitals themselves, and cloud-hosted databases are the common thread across all three.

CareCloud’s six-day window is short next to TriZetto’s yearlong dwell time, but the data set is worse: financial account numbers and government IDs alongside clinical records. Worth checking whether your own vendor’s AWS access controls would catch six days of unauthorized activity, because right now that’s the bar these breaches keep clearing.

Rebecca Lauren