Breach report — Developing
CareCloud Data Breach: What 3.75 Million Patients Need to Know
Reklaim Protect • Published
-1.png&w=3840&q=80)
Breach report — Developing
Reklaim Protect • Published
-1.png&w=3840&q=80)
Health tech company CareCloud confirmed this week that hackers stole personal and medical information on more than 3.75 million patients making it the fifth-largest health-data theft of 2026 so far.
If you've visited a doctor, clinic, or hospital that uses CareCloud for electronic records or billing, your data may be involved even if CareCloud never emailed you directly.
CareCloud is a New Jersey–based company that stores electronic medical records and billing data for tens of thousands of healthcare providers across the United States.
According to a filing with the Department of Health and Human Services (HHS) and reporting from TechCrunch:
CareCloud has not publicly commented on the attack since its initial March disclosure.
The stolen data is unusually sensitive this is not a simple email-and-password leak.
Fields confirmed in breach notifications and regulatory filings include:
That combination makes this breach especially dangerous. Attackers can use medical details to craft convincing phishing messages texts or emails that reference real diagnoses, prescriptions, providers, or billing amounts are much harder to spot than generic scams.
CareCloud serves hospitals, doctor's offices, and other medical practices nationwide. You don't need a CareCloud account yourself to be at risk if your provider uses CareCloud for records or billing, your patient file may be in the stolen dataset.
CareCloud has not published a searchable list of affected providers. If you received care at any U.S. clinic or hospital in recent years, assume you could be affected until you hear otherwise from a provider or see a match in your breach monitoring.
If you use Reklaim Protect, log in and check your dashboard for any new breach hits tied to your monitored email. We scan 15+ breach databases and alert you when your information appears in a new incident including health-sector breaches as they surface in public databases.
Don't click links or call phone numbers in unexpected texts or emails about:
Even if a message looks legitimate, verify through your provider's official website or the phone number on your insurance card not the number in the message.
Banking and payment details were among the stolen fields. Review recent transactions, turn on account alerts with your bank, and report anything unfamiliar immediately.
Social Security numbers were taken. A free credit freeze with Equifax, Experian, and TransUnion makes it harder for someone to open new accounts in your name.
You can lift a freeze temporarily when you legitimately need a credit check.
If you're a Protect member, monitoring is already running in the background:
You don't need to log in every day. We'll email you if something needs your attention.
CareCloud is one of several major healthcare breaches confirmed in 2026:
Health data is a high-value target. Medical records sell for more than credit card numbers on criminal markets because they're harder to change and useful for years of fraud.
The CareCloud breach is one of the largest health-data thefts of 2026 — and the kind of incident where waiting for a company email isn't enough. Names, SSNs, medical records, and financial data are now in criminal hands.
Protect exists so you don't have to track every headline yourself. We monitor breach databases, alert you when your information shows up, and keep broker removal work moving — so you can focus on the practical steps that actually reduce your risk.
We're watching this one closely.
Sources: TechCrunch, HHS Breach Portal. This article is for informational purposes and is not legal or medical advice.
LastPass, NYC Health + Hospitals, and Novo Nordisk made headlines in June 2026. Learn what was exposed, who's at risk, and how to protect yourself.