HomeSecurityCareCloud: Data breach affects over 3.7 million people

CareCloud: Data breach affects over 3.7 million people

One of the largest data breaches in the health technology sector in the US is proving to be the cyberattack that CareCloudThe American company, which provides digital services to healthcare professionals and organizations, announced that the data breach ultimately affected 3,756,469 people, a number significantly higher than initial estimates.

CareCloud: Data Breach

What happened to CareCloud?

CareCloud is a publicly traded healthcare technology company engaged in services such as electronic medical records, medical billing, practice management, and revenue cycle support for healthcare providers.

The incident became known in March, when the company informed the US Securities and Exchange Commission (SEC) that it had experienced a severe disruption to its network operations. The attack caused about eight hours of downtime and affected access to one of its databases.

See also: UT San Antonio: Suspends start of classes due to cyberattack

What was particularly concerning was that the compromised environment contained patient information. At the time, however, there was no clear picture of how many people had been affected or the exact scope of data that the perpetrators may have obtained.

The investigation revealed the true extent

Following the discovery of the attack, CareCloud launched an internal and technical investigationto identify the source of the breach, determine which systems were exposed, and determine whether patient data was accessed.

The results were particularly concerning. In a report submitted to the US Department of Health and Human Services, the company said the total number of people affected was 3.756.469.

According to the notification that began being sent to affected individuals on July 25, an unauthorized third party gained access to one of AWS environments CareCloud's March 10 and 16, 2026.The perpetrators reportedly claimed to have extracted data from databases located in the specific environment.

CareCloud: Data breach affects over 3.7 million people

The type of data remains unknown

While CareCloud has now identified the number of people affected, there is still a significant information gap. The sample notification submitted to the relevant authorities confirms the name-and-surname report, without clearly specifying what other data was included in the information that the attackers may have obtained.

This is particularly important as health technology systems can handle highly sensitive information. Depending on the database affected, even limited information can be used for targeted fraud or social engineering attacks.

See also: Pokémon Center: Data breach affects customers in Britain and Germany

Risk of phishing and identity theft

CareCloud offers affected individuals identity protection services through IDX, for 12 or 24 months, with the option to activate until December 17, 2026. However, the company does not have a direct relationship with most patients, which creates an additional risk.

A user who doesn’t even know about CareCloud might suddenly receive a message stating a “data breach” and assume it’s a scam. Conversely, cybercriminals can take advantage of the confusion by sending fake notifications that impersonate the company or identity protection service.

For this reason, potentially affected individuals should avoid links from unexpected emails, independently verify each message, and closely monitor suspicious activity in their accounts.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

CareCloud: Data breach affects over 3.7 million people

No ransomware group has emerged yet

So far, no known ransomware group or gang has publicly claimed responsibility for the attack on CareCloud.

See also: SilkParasite: Spying on Central Asian governments with 5 new RATs

The incident, however, highlights once again the risks faced by health technology companies. The concentration of large volumes of data in cloud infrastructures creates a particularly attractive target for cybercriminals, while an initial intrusion can lead to significant consequences even if the service outage lasts only a few hours.

CareCloud continues to inform those affected and cooperate with the relevant authorities, while more information is expected to be released as the investigation into the incident is completed.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS