CareCloud health records breach hits 3.7 million

Published August 19, 2026

Attackers broke into servers run by CareCloud, a company that stores medical records for doctors' offices, and stole personal and health data. What started as a report affecting about 350,000 people turned out to affect more than 3.7 million.

Report priority
Medium
Victim
CareCloud

What is known

Attackers got into one of CareCloud's Amazon cloud storage environments between March 10 and March 16 and pulled data out of the databases stored there.

What to do

Watch for a breach notification letter or email from CareCloud or your medical provider, since the exact list of affected patients is not public.

If you receive a CareCloud breach notice, follow its instructions for any free credit monitoring offered and watch your medical and financial statements for unfamiliar activity.

Reported details

CareCloud runs patient record systems for tens of thousands of medical practices inside Amazon's cloud. Between March 10 and March 16, intruders get into one of those cloud environments and copy data out of its databases. The company later finds the intrusion after an electronic health record system used by its clients stops working correctly, and only then realizes how many patient records were taken.

Threat actors accessed one of CareCloud's AWS environments from March 10 to March 16 and exfiltrated data from databases inside it. Stolen fields include names, addresses, Social Security numbers, driver's license numbers, dates of birth, health insurance information, and medical/healthcare information; a small subset of individuals also had full payment card data exposed. State attorney general filings in July initially reported roughly 350,000 affected individuals, but the HHS breach portal now lists 3,756,469. No group has publicly claimed responsibility, and CareCloud has not disclosed whether a ransom was paid.