Health tech company CareCloud confirmed this week that hackers stole personal and medical information on more than 3.75 million patients making it the fifth-largest health-data theft of 2026 so far.
If you've visited a doctor, clinic, or hospital that uses CareCloud for electronic records or billing, your data may be involved even if CareCloud never emailed you directly.
What happened
CareCloud is a New Jersey–based company that stores electronic medical records and billing data for tens of thousands of healthcare providers across the United States.
According to a filing with the Department of Health and Human Services (HHS) and reporting from TechCrunch:
- Hackers accessed a cloud storage environment for six days in March 2026
- Patient data was exfiltrated from CareCloud's Amazon Web Services account
- The company first disclosed the breach in March; the full scale (3.75M+ people) was confirmed in an HHS update on August 18–19, 2026
- The victim count was revised upward in a follow-up update and may still change
CareCloud has not publicly commented on the attack since its initial March disclosure.
What was stolen
The stolen data is unusually sensitive this is not a simple email-and-password leak.
Fields confirmed in breach notifications and regulatory filings include:
- Names and postal addresses
- Social Security numbers
- Medical and health information
- Government-issued IDs (passports, driver's licenses)
- Banking and financial information
That combination makes this breach especially dangerous. Attackers can use medical details to craft convincing phishing messages texts or emails that reference real diagnoses, prescriptions, providers, or billing amounts are much harder to spot than generic scams.
Who might be affected
CareCloud serves hospitals, doctor's offices, and other medical practices nationwide. You don't need a CareCloud account yourself to be at risk if your provider uses CareCloud for records or billing, your patient file may be in the stolen dataset.
CareCloud has not published a searchable list of affected providers. If you received care at any U.S. clinic or hospital in recent years, assume you could be affected until you hear otherwise from a provider or see a match in your breach monitoring.
-1.png&w=3840&q=80)
