01Summary
CareCloud had a network disruption on 16 March 2026. Investigators found an unauthorised party had accessed one AWS EHR environment from 10 to 16 March. A filing with the US Department of Health and Human Services on 18 August 2026 put the number affected at more than 3.75 million. Exposed data may include Social Security numbers, financial account details and medical records. No group has claimed the attack.
02Victims and impact
Countries affected
- United States
03Data exposed
Data types
- Social Security numbers
- Financial account details
- Medical records
04Timeline
- 2026-03-10Unauthorised access begins.
- 2026-03-16Network disruption detected.
- 2026-08-18HHS filing confirms 3.75 million affected.
05Disclosure and media
Publishing organisations
- TechCrunch
- SecurityWeek
- HIPAA Journal
06Sources
References
- [1]TechCrunch: https://techcrunch.com/2026/08/19/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/
- [2]HIPAA Journal: https://www.hipaajournal.com/carecloud-data-breach/









