• Tech Tech

CareCloud confirms breach affects 3.75 million US patients, far more than first disclosed

This incident also fits into a broader pattern of large healthcare-related data exposures.

A reception area with a blue wall featuring the CareCloud logo and two Dell monitors on a desk.

Photo Credit: Image © 2026 by Zain.3nov is licensed under CC BY 4.0

Millions of patients who entrusted their health information to back-end software company CareCloud are now learning just how far the fallout from a March cyber incident may extend.

CareCloud has confirmed that 3,756,469 people were affected, turning what first appeared to be a corporate disclosure into a major privacy threat for patients across the country.

Here's what to know

In March, CareCloud notified the U.S. Securities and Exchange Commission about the incident. The company provides cloud-based electronic health record, billing, and clinical documentation tools to healthcare providers around the country.

Public reporting by Top Class Actions noted that the scale of the breach became clearer after it appeared on the U.S. Department of Health and Human Services Office for Civil Rights portal, which lists 3,756,469 affected individuals.

Investigators concluded that a hacker accessed one of the company's Amazon Web Services environments from March 10 through March 16. CareCloud's breach notice says the issue came to light on March 16, when it detected a network disruption in its CareCloud Health division.

By June 24, CareCloud said the information involved varied from person to person. Depending on the individual, the exposed data may have included names, addresses, birth dates, Social Security numbers, driver's license or other government ID numbers, financial account numbers, credit or debit card numbers, and medical or health insurance details.

More background

Breaches involving names, birth dates, Social Security numbers, financial details, and medical information can lead to credit fraud, insurance abuse, and identity theft.

Patients often do not directly choose the outside technology vendors responsible for handling their records, yet they can still face the consequences when a company's cybersecurity protections fail or when large stores of sensitive data become targets.

CareCloud says it has neither received reports of identity fraud or misuse tied to the breach nor found signs of unauthorized activity continuing after March 16.

This incident also fits into a broader pattern of large healthcare-related data exposures. In July, Unlimited Technology Systems told more than 3.8 million patients that an October 2025 breach may have exposed their personal and protected health information.

What can be done?

CareCloud said notification letters started going out in July, and affected consumers are being offered free IDX identity theft protection for either 12 or 24 months, depending on their circumstances.

The no-cost IDX package includes credit monitoring and a $1 million insurance reimbursement policy. People affected by the breach can enroll before the December 17 deadline at app.idx.us/account-creation/protect or call IDX at 866-329-9984 from 9 a.m. to 9 p.m. ET, Monday through Friday.

Details of the incident are listed on the HHS Office for Civil Rights breach portal. Given the kinds of information that may have been exposed, affected people may want to monitor bank accounts, credit reports, insurance statements, and notices involving unfamiliar medical services or billing activity.

CareCloud says it has eliminated the threat, but breaches involving health and financial data can create problems months or even years later.

Although CareCloud says it has not seen signs of further unauthorized activity since March 16, its own breach notice acknowledged that the intruder "claimed to have exfiltrated data from databases within that environment."

Where can I learn more?

These articles are unrelated to the CareCloud breach, but they point to the same pressure point: public trust in large organizations.

Whether the focus is healthcare, regulation, or a global brand, the scrutiny often comes back to accountability, transparency, and consumer confidence.

• Bausch + Lomb has kept over 450,000 pounds of contact lens waste out of landfills.

• Zara parent Inditex faced backlash after carbon emissions increased alongside an operational shipping change.

For patients dealing with the aftermath of a breach this large, that broader accountability question still matters. When trust breaks down, everyday people are often the ones left to deal with the consequences.

Get TCD's free newsletters for easy tips, smart advice, and a chance to earn $5,000 toward home upgrades. To see more stories like this one, change your Google preferences here.

Cool Divider