New York Sunday, August 30, 2026

Boldest Voice

Search

Technology

CareCloud data breach exposes medical records of 3.75 million patients

A cyberattack on healthcare technology provider CareCloud has exposed the personal and medical information of more than 3.75 million people, making it one of the largest healthcare data breaches of 2026.

Healthcare data breach exposes 3.75M patient records

More than 3.75 million people had their personal information and medical records stolen after hackers breached a cloud environment operated by CareCloud, a major provider of electronic medical record technology for healthcare organizations across the United States. The incident, which occurred in March, has been reported to federal health regulators and is now among the largest healthcare data breaches disclosed so far this year.

CareCloud supplies electronic medical record systems and related services to tens of thousands of healthcare providers nationwide. That means many of the affected individuals may never have interacted with the company directly — a doctor's office, clinic, or other medical practice using CareCloud's technology could have handled their information. The breach highlights a growing risk for patients whose data is stored in third-party systems they may not know about.

According to a breach notice filed with the California Attorney General, CareCloud experienced a network disruption on March 16. The company brought in outside cybersecurity experts to investigate and later determined that an unauthorized third party had access to one of its Amazon Web Services environments between March 10 and March 16. The attacker claimed to have taken data from databases inside that environment. CareCloud said it found no evidence of continued unauthorized activity after the incident was contained.

Early disclosures suggested that hundreds of thousands of people were affected, but that figure later climbed dramatically. CareCloud has now confirmed that more than 3.75 million individuals were impacted, according to federal health regulators. The company also reported the attack to law enforcement and secured the affected environment.

The stolen information goes well beyond email addresses or phone numbers. Depending on the individual, the exposed data may include Social Security numbers, banking information, medical records, insurance details, and other sensitive personal data. Security experts warn that this combination of information can fuel identity theft, put financial accounts at risk, and make phishing scams far more convincing because criminals can reference real medical history or personal details.

One of the most serious concerns is medical identity theft. Unlike a password, a person's medical history cannot simply be changed after a breach. A criminal could use stolen insurance or personal information to seek medical care under someone else's identity, or fraudulent claims could be filed under a victim's health insurance. In some cases, incorrect treatment or medical information could eventually end up in a person's records, creating problems that extend beyond financial fraud.

The Federal Trade Commission advises people who suspect medical identity theft to review their medical records and insurance statements carefully, looking for unfamiliar treatments, providers, prescriptions, or charges. CareCloud has offered affected individuals complimentary identity protection services through IDX. Those who received a notification letter should check it for enrollment instructions and deadlines.

For people affected by the breach, experts recommend starting with the notification letter to see which specific types of information were exposed, since not everyone had the same data compromised. If a Social Security number was involved, freezing credit with Equifax, Experian, and TransUnion can help prevent criminals from opening new accounts. Federal law allows consumers to freeze and unfreeze their credit for free. However, a credit freeze cannot block every form of identity theft, so monitoring bank accounts, credit cards, and credit reports for suspicious activity remains essential.

Brooke Griffin

Author

Breaking News Editor

Brooke Griffin covers public affairs, politics, business, culture and daily news for Boldest Voice. The role focuses on verification, context, and clear explanations for readers.

Read on