Healthcare data breach exposes 3.75M patient records
More than 3.75 million people have had personal and medical information stolen after hackers breached a cloud environment used by CareCloud, a US provider of electronic medical record technology. The company serves tens of thousands of healthcare providers, meaning many affected individuals may never have interacted with CareCloud directly, yet had their data exposed through a doctor's office or other provider using its systems. The breach is among the largest healthcare data incidents reported so far in 2026.
CareCloud detected a network disruption on 16 March 2026 and later found that an unauthorised third party had accessed one of its Amazon Web Services environments between 10 and 16 March, with the attacker claiming to have taken data from internal databases. Initial disclosures put the number affected in the hundreds of thousands, but this figure has since risen sharply to over 3.75 million, according to federal health regulators. The stolen data varies by individual but may include Social Security numbers, banking details and medical records, raising risks of identity theft, financial fraud and medical identity theft, where criminals use stolen details to obtain treatment or file fraudulent insurance claims under someone else's name.
- CareCloud breach exposed data of 3.75 million healthcare patients
- Hackers accessed AWS environment between 10–16 March 2026
- Stolen data may enable identity theft and medical identity theft