/ Sep 20, 2026
Trending
Health data technology firm CareCloud has confirmed that hackers stole the personal information and medical records of more than 3.75 million people in a data breach. The company disclosed the scale of the incident in a filing with the Department of Health and Human Services (HHS) on Monday, marking the first official confirmation of the breach's size.
The number of affected victims was reportedly revised upward in an update on Tuesday, though it remains unclear whether the figure will rise further.
The New Jersey-based company, which provides electronic medical record storage to tens of thousands of healthcare providers across the United States, serves millions of patients. CareCloud handles large volumes of patient data and billing information on behalf of hospitals, doctor's offices, and other medical practices.
CareCloud first disclosed the breach in March, stating that hackers had accessed patients' medical data stored in one of its cloud storage environments over a six-day period. The company later revealed in data breach notifications that the attackers exfiltrated data from its Amazon Web Services account and stole extensive patient records.
The stolen data includes patients' names, postal addresses, Social Security numbers, and medical and health information. Hackers also obtained government-issued identification numbers, such as passports and driver's licenses, as well as banking and financial details.
The breach is now confirmed as the fifth-largest theft of health data in 2026 so far, according to the company's filing with federal regulators.
The CareCloud incident follows several other sizable healthcare breaches confirmed this year. Tech giant TriZetto confirmed in March that a 2024 data breach affected 3.4 million people's data. Additionally, an unspecified number of individuals had their data stolen during a July data breach at healthtech billing software maker Craneware.
According to HHS's running tally of healthcare data breaches, dental insurance giant DentaQuest has experienced the largest data breach this year, with at least 15 million people's personal and health information affected.
This breach underscores the ongoing challenges healthcare organizations face in protecting sensitive patient data under the Health Insurance Portability and Accountability Act (HIPAA). The incident highlights the importance of robust cybersecurity measures to safeguard electronic protected health information (ePHI) and comply with federal regulations.
CareCloud has not publicly commented on the cyberattack beyond its initial disclosure and subsequent notifications.
#CareCloud, #DataBreach, #HealthcareSecurity, #HIPAA, #CyberAttack
It is a long established fact that a reader will be distracted by the readable content of a page when looking at its layout. The point of using Lorem Ipsum is that it has a more-or-less normal distribution
Copyright PopularTechNews. 2024