CareCloud says a March data breach affected more than 3.7 million people and involved highly sensitive records. Here’s what was stolen, why it matters, and how you can respond now.
Table of Contents
What Happened in the CareCloud Data Breach?
CareCloud detected a network intrusion in mid-March after problems affected an electronic health record system used to manage patient information.
Its investigation found that attackers accessed one Amazon Web Services environment between March 10 and March 16.
Amazon Web Services, or AWS, is a cloud platform companies use to store data and run online systems.
CareCloud said the attackers took information from databases inside that environment.
Early reports suggested roughly 350,000 people were affected. However, the HHS breach tracker later showed a much larger number.
It listed 3,371,508 people on August 17, then increased the total to 3,756,469 on August 18.
HHS confirmed to SecurityWeek that the larger figure was accurate and reflected the latest information CareCloud provided.
CareCloud has not publicly identified the attackers or said whether it paid any ransom.
Sensitive identity and health information can remain useful to criminals long after a breach. They may use it for fraud, phishing, or impersonation.
Many people also do not realize their information was leaked in another breach until suspicious activity appears later.
If you are unsure whether your information was leaked, automatic monitoring can help you spot problems earlier.
Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Was Affected and What Data Was Stolen?
The HHS breach tracker says 3,756,469 people were affected by the CareCloud data breach.
CareCloud said the stolen information included:
- Names
- Home addresses
- Social Security numbers
- Driver’s license numbers
- Dates of birth
- Health insurance information
- Medical and healthcare information
For a very limited group, the attackers also obtained full payment card information.
The source does not specify which data types applied to each affected person.
Futureproof monitors your information for data leaks 24/7 and guides you with clear steps to keep it safer from scams.
Run a free checkWhat We Know About How Attackers Got Into CareCloud
CareCloud said attackers entered one of its AWS environments and had access between March 10 and March 16.
However, the company has not publicly explained exactly how they first gained access.
That means the technical method used to start the attack remains unknown.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
