VMTech
Discuss a project

CareCloud reports theft of records affecting over 3.75 million patients

CareCloud reports theft of records affecting over 3.75 million patients

CareCloud has reported to the US Department of Health and Human Services that a March cyberattack exposed the personal information and medical records of more than 3.75 million people. The New Jersey-based healthcare technology company provides electronic medical record storage for tens of thousands of providers across the United States.

The filing is the first confirmation of the breach’s scale. The affected-person total was reportedly revised upward in an update the following day, and it remains unclear whether CareCloud expects the figure to increase further. The incident is now the fifth-largest theft of healthcare data confirmed in 2026 so far.

Cloud environment accessed for six days

CareCloud disclosed the incident in March, saying that hackers had accessed patient medical data held in one of its cloud storage environments for six days. In subsequent breach notifications, the company said the attackers exfiltrated data from its Amazon Web Services account.

The stolen material includes names, postal addresses, Social Security numbers, and medical and health information. CareCloud also said the data taken included government-issued identification numbers, such as passport and driver’s licence numbers, along with banking and financial information.

CareCloud handles patient data and billing information for hospitals, doctors’ offices, and other medical practices. Its role as a service provider means a single incident can affect patients connected to a large number of healthcare organisations rather than one provider alone.

Scale adds to a difficult year for healthcare data

CareCloud had begun notifying patients of the theft in CareCloud patient data theft notifications, while the latest HHS filing establishes a far larger confirmed total. The company has not publicly commented further on the cyberattack since its March disclosure.

Other major healthcare incidents have also been confirmed this year. TriZetto said in March that a 2024 breach affected 3.4 million people, while healthtech billing software maker Craneware reported a July breach with an unspecified number of affected individuals. HHS lists DentaQuest as having the largest healthcare breach of the year to date, affecting at least 15 million people’s personal and health information.

Business implication

Healthcare providers and their technology suppliers should account for the concentration of clinical, identity, and payment data in shared cloud environments, and ensure that oversight of storage access and incident response extends to every organisation handling that data.

#healthcaresecurity#databreach#cloudsecurity#patientdata
Open analytics
On the site 1 views
min read 3 19.08.2026
Instagram

CareCloud reports theft of records affecting over 3.75 million patients

Open the post on Instagram ↗