CareCloud Data Breach: 345,000 Notified After Medical Records Stolen

CareCloud Data Breach: 345,000 Notified After Medical Records Stolen

A CareCloud data breach affected at least 345,000 people and included medical, financial, and identity records. Here’s what was stolen, why it matters, and how you can respond more safely.

What Happened?

According to TechCrunch, CareCloud — a U.S. health technology company — began notifying people after a March 2026 data breach.

Hackers accessed one of the company’s six patient data stores from March 10 through March 16.

The store was hosted on Amazon Web Services, a cloud service companies use to keep information online.

CareCloud first reported the incident to regulators on March 27. New state filings now show that at least 345,000 people were affected.

Who Was Affected and What Data Was Leaked?

State filings show that at least 345,000 people across the United States were affected. The number may rise as more disclosures are filed.

CareCloud stores patient data for more than 45,000 healthcare providers. However, the company has not said how many providers had patients in the affected store.

Confirmed leaked data included:

  • Names and postal addresses
  • Social Security numbers
  • Passport and driver’s license numbers
  • Other government identification numbers
  • Bank account information
  • Payment card numbers
  • Medical and health-related information

CareCloud has not said whether every affected person had every type of information stolen.

This mix of information can help criminals attempt identity theft, financial fraud, and highly personal phishing messages.

Medical and billing details can also make a fake call from an insurer, doctor, or bank seem more believable.

Your information may appear in older breaches you never heard about. Regular monitoring can help you discover those risks sooner.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Check if your email was found in a leak

Futureproof monitors your information for data leaks 24/7 and guides you with clear steps to keep it safer from scams.

Run a free check

How Hackers Reached CareCloud’s Patient Data

CareCloud confirmed that hackers entered a patient data store hosted on Amazon Web Services.

However, the company has not explained how they gained access.

A hacker claimed to have exfiltrated data, meaning the information was copied from the system and taken elsewhere.

TechCrunch reported that no ransomware or extortion group had publicly claimed responsibility for the attack.