Health tech company CareCloud confirmed this week that hackers stole personal and medical information on more than 3.75 million patients making it the fifth-largest health-data theft of 2026 so far.
If you've visited a doctor, clinic, or hospital that uses CareCloud for electronic records or billing, your data may be involved even if CareCloud never emailed you directly.
What happened
CareCloud is a New Jersey–based company that stores electronic medical records and billing data for tens of thousands of healthcare providers across the United States.
According to a filing with the Department of Health and Human Services (HHS) and reporting from TechCrunch:
- Hackers accessed a cloud storage environment for six days in March 2026
- Patient data was exfiltrated from CareCloud's Amazon Web Services account
- The company first disclosed the breach in March; the full scale (3.75M+ people) was confirmed in an HHS update on August 18–19, 2026
- The victim count was revised upward in a follow-up update and may still change
CareCloud has not publicly commented on the attack since its initial March disclosure.
What was stolen
The stolen data is unusually sensitive this is not a simple email-and-password leak.
Fields confirmed in breach notifications and regulatory filings include:
- Names and postal addresses
- Social Security numbers
- Medical and health information
- Government-issued IDs (passports, driver's licenses)
- Banking and financial information
That combination makes this breach especially dangerous. Attackers can use medical details to craft convincing phishing messages texts or emails that reference real diagnoses, prescriptions, providers, or billing amounts are much harder to spot than generic scams.
Who might be affected
CareCloud serves hospitals, doctor's offices, and other medical practices nationwide. You don't need a CareCloud account yourself to be at risk if your provider uses CareCloud for records or billing, your patient file may be in the stolen dataset.
CareCloud has not published a searchable list of affected providers. If you received care at any U.S. clinic or hospital in recent years, assume you could be affected until you hear otherwise from a provider or see a match in your breach monitoring.
What you should do now
1. Check your breach monitoring
If you use Reklaim Protect, log in and check your dashboard for any new breach hits tied to your monitored email. We scan 15+ breach databases and alert you when your information appears in a new incident including health-sector breaches as they surface in public databases.
2. Treat medical-themed messages with extra caution
Don't click links or call phone numbers in unexpected texts or emails about:
- Appointments you didn't schedule
- Medical bills or insurance claims
- Prescription refills or pharmacy notices
Even if a message looks legitimate, verify through your provider's official website or the phone number on your insurance card not the number in the message.
3. Watch your financial accounts
Banking and payment details were among the stolen fields. Review recent transactions, turn on account alerts with your bank, and report anything unfamiliar immediately.
4. Consider a credit freeze
Social Security numbers were taken. A free credit freeze with Equifax, Experian, and TransUnion makes it harder for someone to open new accounts in your name.
You can lift a freeze temporarily when you legitimately need a credit check.
What Reklaim Protect is doing
If you're a Protect member, monitoring is already running in the background:
- Breach database monitoring we check whether your email appears in new incidents, including health-sector breaches as they're added to public sources
- Broker removal still active even when health records leak, your name, address, and phone shouldn't stay on data-broker lists; removal work continues
- Plain-English alerts if we find a match, you get clear next steps, not a wall of security jargon
You don't need to log in every day. We'll email you if something needs your attention.
How this fits the bigger picture
CareCloud is one of several major healthcare breaches confirmed in 2026:
- TriZetto — 3.4 million people affected (2024 breach, confirmed March 2026)
- Craneware — billing software breach in July 2026 (scale still unspecified)
- DentaQuest — at least 15 million people affected (largest healthcare breach of 2026 so far, per HHS)
Health data is a high-value target. Medical records sell for more than credit card numbers on criminal markets because they're harder to change and useful for years of fraud.
The bottom line
The CareCloud breach is one of the largest health-data thefts of 2026 — and the kind of incident where waiting for a company email isn't enough. Names, SSNs, medical records, and financial data are now in criminal hands.
Protect exists so you don't have to track every headline yourself. We monitor breach databases, alert you when your information shows up, and keep broker removal work moving — so you can focus on the practical steps that actually reduce your risk.
We're watching this one closely.
Sources: TechCrunch, HHS Breach Portal. This article is for informational purposes and is not legal or medical advice.
Related articles
Three Major Breaches in the News — and What They Mean for You
LastPass, NYC Health + Hospitals, and Novo Nordisk made headlines in June 2026. Learn what was exposed, who's at risk, and how to protect yourself.
-1.png&w=3840&q=80)
