Skip to content
Data breachUnknown

CareCloud AWS environment breach exposes 3.7 million patients' records

Healthcare IT company CareCloud disclosed that an unauthorized party accessed one of its AWS environments and stole data on 3,756,469 people, including Social Security numbers, financial details and medical information.

Victim
CareCloud, Inc.
users
3.8M

On 27 March 2026, CareCloud (a publicly traded U.S. provider of electronic health records, medical billing, practice management and revenue-cycle software) disclosed in an SEC filing that an unauthorized third party had accessed one of its Amazon Web Services environments between 10 and 16 March 2026 and claimed to have exfiltrated data from databases hosted there.

The full scale only emerged months later. CareCloud began mailing notification letters on 25 July 2026, and by the end of July state attorney general filings in New Hampshire, Massachusetts, Texas, Maine and California counted at least 345,000 people. On 19 August 2026, a report to the U.S. Department of Health and Human Services put the total at 3,756,469 individuals, making it one of the largest U.S. health data breaches of the year.

What was exposed

According to the notification letters, the stolen data includes names, postal addresses, Social Security numbers, passport and driver's license numbers, bank account and payment card details, and medical and health information. CareCloud is offering affected people 12 to 24 months of identity protection through IDX.

No ransomware or extortion group has publicly claimed the attack, and CareCloud has not said how the intruders obtained access to the AWS environment or whether a ransom was demanded.

Why it matters

CareCloud stores and processes records on behalf of tens of thousands of healthcare providers, so a single compromised cloud environment translated into exposure for millions of patients who never dealt with the company directly. The five-month gap between the initial SEC disclosure and the final HHS count is typical of breaches at healthcare service providers, where the vendor has to reconcile data across many client practices before it can say who was affected.

Timeline

  1. An unauthorized third party gains access to one of CareCloud's AWS environments; activity continues until 16 March.

  2. CareCloud discloses the incident in a Form 8-K filing with the U.S. Securities and Exchange Commission.

  3. CareCloud begins mailing notification letters and offers 12 to 24 months of IDX identity protection.

  4. State attorney general filings show at least 345,000 people notified so far.

  5. A filing with the HHS Office for Civil Rights raises the total to 3,756,469 affected individuals.

Sources

  1. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/
  2. techcrunch.comhttps://techcrunch.com/2026/08/19/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/
  3. techcrunch.comhttps://techcrunch.com/2026/07/30/carecloud-begins-to-notify-hundreds-of-thousands-after-hackers-stole-medical-records/

Related incidents