CareCloud confirms 3.7M patients had their medical records stolen in data breach

← Back to the feed

CareCloud confirms 3.7M patients had their medical records stolen in data breach

TechCrunch · 2 hours ago

Health data company CareCloud has confirmed that hackers stole the personal and medical information of more than 3.75 million people, making it the fifth-largest healthcare data breach recorded in the US so far this year. The New Jersey-based firm, which provides electronic medical record storage to tens of thousands of healthcare providers across the country, disclosed the scale of the incident in a filing with the Department of Health and Human Services this week, though the breach itself first occurred in March.

The stolen data includes patients' names, postal addresses, Social Security numbers, medical and health records, government identification numbers such as passports and driving licences, and banking details. CareCloud has said the hackers accessed its Amazon Web Services cloud storage environment over a six-day period, but the company has not commented publicly since March and its chief executive has not responded to questions about whether a ransom was paid or who is accountable for security. The breach follows other major healthcare data incidents this year, including a 3.4 million-person breach at TriZetto and a still-unquantified breach at Craneware, with dental insurer DentaQuest's 15 million-person breach remaining the largest so far.

  • CareCloud confirms 3.75 million patients' data stolen in March breach
  • Stolen data includes SSNs, medical records, IDs and banking details
  • Fifth-largest US healthcare breach of 2026; CEO not responding to queries

New here? Start with this

CareCloud is a US company that provides electronic medical record software and cloud storage to a large number of healthcare providers across the country. Because it holds so much sensitive data on behalf of other organisations, it is the kind of company hackers specifically target, since breaching one firm can expose the records of millions of patients at once who may never have directly interacted with CareCloud themselves.

Healthcare data is especially valuable to criminals because it typically combines financial details, government ID numbers and medical history in one place, making it useful for identity theft, fraud and blackmail. Breaches of this kind are usually reported to US regulators under health privacy laws, which is how such incidents come to light, though there is often a lag between when a breach happens and when the public learns its true scale.

This incident sits within a wider pattern of large-scale breaches at healthcare and health-technology firms in the US this year, several affecting millions of patients each. That trend has raised broader questions about how well such companies protect the medical and personal data they store on behalf of others, and about accountability when breaches occur.

Cybersecurity Technology

Read the full article at the source →