Healthcare2 mins read

CareCloud breach exposes medical records of more than 3.75 million patients

A cyberattack at CareCloud exposed personal, medical, and financial information for more than 3.75 million people, making it one of the largest reported U.S. healthcare data breaches of 2026.

What CareCloud confirmed

CareCloud confirmed with federal regulators that hackers stole personal information and medical records belonging to more than 3.75 million people. The company detailed the March data breach in a filing with the Department of Health and Human Services, and the affected count was reportedly revised upward in an update.

The disclosure makes the incident the fifth-largest theft of health data in 2026 so far, according to the TechCrunch report.

What data was stolen

The stolen data includes patients’ names, postal addresses, Social Security numbers, medical and health information, government-issued identification numbers such as passports and driver’s licenses, and banking and financial information.

For patients, the key takeaway is that this was not limited to contact details; the exposed categories span identity, health, and financial records.

Why the breach reaches so widely

CareCloud provides electronic medical record storage to tens of thousands of healthcare providers across the United States and handles patient data and billing information for hospitals, doctors’ offices, and other medical practices.

The company previously said hackers accessed patients’ medical data stored in one cloud storage environment over six days, and later said data was exfiltrated from its Amazon Web Services account.

How it fits into a broader healthcare breach trend

The CareCloud breach follows several sizable healthcare breaches confirmed this year. Tech giant TriZetto confirmed in March that a 2024 breach affected 3.4 million people’s data, while TechCrunch also reported an unspecified number of people had data stolen during a July breach at health tech billing software maker Craneware.

According to HHS’ running tally cited in the report, DentaQuest has had the largest healthcare data breach this year so far, affecting at least 15 million people’s personal and health information.

Discover More

    Cybersecurity-themed illustration used for a report on AI-generated exploit scripts targeting industrial control systems
    AI speeds ICS attacks

    U.S. agencies warn AI-generated exploit scripts are raising risks for exposed Siemens S7 industrial controllers.

    CybersecurityIndustrial Control Systems
    A T-Mobile store in Times Square with bright pink T-Mobile signage.
    T-Mobile Cut Off Hackers

    T-Mobile reportedly stopped Salt Typhoon activity by physically severing a compromised system’s connection.

    CybersecurityT-Mobile