Technology
CareCloud data breach exposes 3.75 million patient records
An unauthorized party accessed CareCloud's Amazon Web Services environment in March 2026, compromising personal information and medical records.
The short version
- Healthcare technology provider CareCloud reported a cyberattack affecting more than 3.75 million people.
- An unauthorized third party accessed a CareCloud Amazon Web Services environment from March 10 to March 16, 2026.
- Exposed information varies per person and may include Social Security numbers, banking details, and medical records.
- CareCloud reported the incident to law enforcement and health regulators, and is offering affected individuals free identity protection through IDX.
Key facts
- CareCloud detected a network disruption on March 16, 2026, and determined an unauthorized third party had accessed an Amazon Web Services environment between March 10 and March 16.[Fox News]
- Data breaches reported to federal health regulators indicate that more than 3.75 million individuals were affected by the incident.[Fox News]
- Compromised information varies by individual but may include Social Security numbers, banking information, and medical records.[Fox News]
- CareCloud notified law enforcement, federal health regulators, and the California Attorney General, and retained third-party cybersecurity experts to investigate.[Fox News]
- Investigators found no evidence of continued unauthorized access following the containment of the incident after March 16, 2026.[Fox News]
What remains uncertain
- The full extent to which stolen data has been or could be misused for identity theft or financial fraud remains unknown.[Fox News]