
AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
The health IT company told the SEC in March that an intruder reached one of six health record environments. It later told HHS that more than 3.7 million people were affected.
What happened
CareCloud, a New Jersey company that stores electronic health records (EHRs) for more than 45,000 providers, filed an 8-K with the US Securities and Exchange Commission in March 2026. It said a network disruption on 16 March hit 1 of its 6 EHR environments for about eight hours, that an unauthorised third party was responsible, and that on 24 March it judged the incident material. Later notices to state attorneys general, reported by TechCrunch, said the intruder had access from 10 to 16 March to data hosted on Amazon Web Services (AWS). In August the company's filing with the Department of Health and Human Services (HHS) put the count at more than 3.7 million people.
Confirmed vs. claimed
Confirmed by CareCloud: the intrusion, the dates, and that patient data was involved. According to TechCrunch, the stolen data includes names, postal addresses, Social Security numbers, medical information, government ID numbers such as passport and driver's licence numbers, and banking details.
Reported: the company told regulators that the attacker "claimed to have exfiltrated data" from databases. No group has publicly taken credit, and it is not known whether a ransom was demanded or paid.
Who is affected
Patients of US doctors, clinics and hospitals that use CareCloud. Letters began going out in July; your notice may name your provider rather than CareCloud.
What to do
- Enrol in any credit monitoring offered in your letter.
- Place a credit freeze and review your credit reports.
- Check insurer statements for treatment you did not receive.
- If your bank details were included, ask your bank about extra monitoring.
- See our guide on what to do after a data breach notice.
Sources
- CareCloud — Form 8-K, Item 1.05 material cybersecurity incident (Mar 2026) Primary
- TechCrunch — CareCloud confirms 3.7M patients had their medical records stolen in data breach (19 Aug 2026) Secondary
- TechCrunch — CareCloud begins to notify hundreds of thousands after hackers stole medical records (30 Jul 2026) Secondary
- SecurityWeek — CareCloud data breach impact grows to 3.7 million individuals (Aug 2026) Secondary
More breaches in United States
- IDScan.net — 01 Sep 2026
- Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) — 27 Aug 2026
- Boston Scientific — 26 Aug 2026
- Aesto Health — 14 Aug 2026
- DentaQuest — 17 Jul 2026