CareCloud Healthcare IT Data Breach Affects More Than 3.7 Million Patients

Views: 55 views

454/69 Friday, August 21, 2026

CareCloud, a U.S.-based healthcare information technology provider that manages electronic health record systems and medical data management services, has disclosed a data breach affecting more than 3.7 million patients. The incident is particularly significant because the company’s systems store personal information and may include sensitive health data. The exposure could lead to privacy risks and the potential misuse of stolen information for malicious purposes.

According to the preliminary investigation, between March 10 and March 16, 2026, threat actors gained unauthorized access to the company’s AWS cloud environment and allegedly exfiltrated data from the database. The attack also caused an eight-hour service disruption. At this time, the company has not disclosed the full scope of the exposed data beyond patients’ full names, and no ransomware group has claimed responsibility for the incident. CareCloud began sending notification letters to affected individuals on July 25 and offered identity protection services to help mitigate potential impact.

To reduce risk, users should exercise heightened caution against phishing attacks that may use leaked information to make scams appear more convincing. Users should avoid providing additional personal information or clicking links in suspicious emails or messages. They should also regularly review personal accounts and financial transactions for unusual activity to help prevent identity misuse.

Source: https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/