Healthcare technology company CareCloud has confirmed that hackers stole personal information and medical records belonging to more than 3.75 million people during a cyberattack earlier this year.
The latest figure represents a dramatic increase from the roughly 350,000 victims initially identified through state breach disclosures. According to reporting from SecurityWeek, the U.S. Department of Health and Human Services updated its breach tracker on August 18 to show 3,756,469 affected individuals.
HHS subsequently confirmed that the figure was accurate and reflected the most recent information provided to the agency.
Hackers Accessed CareCloud Environment for Six Days
The incident dates back to March 2026.
CareCloud initially disclosed that it detected a security incident on March 16 after experiencing a temporary network disruption in its CareCloud Health division. The disruption affected functionality and data access within one of the company’s six electronic health record environments for approximately eight hours.
Further investigation determined that an unauthorized party had gained access to a CareCloud cloud account supporting the affected EHR environment.
According to breach notifications subsequently filed with regulators, the attackers had access to the environment between March 10 and March 16.
CareCloud later confirmed that the compromised infrastructure was hosted on Amazon Web Services and that the threat actor claimed to have exfiltrated databases from the environment.
Medical, Identity and Financial Data Stolen
The information compromised varies depending on the individual, but the breach involved a substantial amount of highly sensitive patient information.
TechCrunch reports that the stolen data includes names, postal addresses, Social Security numbers, medical information, and health-related information.
Regulatory breach notifications also identify additional potentially compromised information, including:
- Dates of birth
- Driver’s license numbers
- Other government-issued identification numbers
- Passport information
- Financial account numbers
- Credit and debit card information
- Health insurance information
- Medical and healthcare records
SecurityWeek reported that full payment card information was exposed for only a very limited subset of affected individuals.
The combination of medical records, government identification information, financial details, and Social Security numbers makes the incident particularly sensitive because much of that information cannot simply be changed like a password.
Initial Victim Count Was Far Lower
When CareCloud began notifying victims in July, filings with several state attorneys general indicated that approximately 345,000 people had been affected.
That number was never expected to represent the complete breach because individual state filings generally count only residents of those states.
The scale became significantly clearer when the incident appeared on the federal healthcare breach tracker. The HHS entry initially listed 3,371,508 affected individuals before being revised the following day to 3,756,469.
The new total makes the CareCloud incident one of the largest healthcare data breaches reported in the United States during 2026.
CareCloud Stores Records for Thousands of Healthcare Providers
CareCloud provides electronic health record, billing, practice management, and other healthcare technology services to medical organizations across the United States.
The company stores patient information on behalf of tens of thousands of healthcare providers, meaning a compromise of one centralized environment can expose data originating from numerous medical practices.
In its August SEC filing, CareCloud said its forensic investigation determined that the attacker exfiltrated personally identifiable information and protected health information associated with a substantial number of individuals.
The company said it found no evidence that its other platforms, divisions, systems, data, or environments were affected.
No Threat Group Has Publicly Claimed the Attack
CareCloud has not identified the attackers, and no known ransomware or extortion group has publicly taken responsibility for the breach.
It also remains unclear whether CareCloud received or paid a ransom demand.
The company says it found no evidence of additional unauthorized activity after March 16 and that all affected systems remain operational.
CareCloud has notified affected healthcare-provider customers and is continuing to provide required notifications to patients and regulators.
The incident has also resulted in multiple class-action lawsuits alleging that personal information was compromised. Those cases were consolidated in federal court in Florida in June.
For affected patients, the long-term risk extends beyond conventional account compromise. Medical records, Social Security numbers, government identification information, and financial details can support identity theft, fraudulent insurance claims, targeted phishing, impersonation, and other forms of fraud long after the original breach occurred.