Skip to main content
LiMP VPN
All news

CareCloud: 3.7M Patient Records Stolen in AWS Cloud Breach

CareCloud: 3.7M Patient Records Stolen in AWS Cloud Breach

In short: CareCloud, a New Jersey-based healthcare software provider serving over 45,000 medical practices across the US, has confirmed that hackers spent six days inside one of its Amazon Web Services EHR cloud environments in March 2026. The attackers stole the personal, medical, and financial data of 3,756,469 patients: names, Social Security numbers, medical records, passports, bank account numbers, and credit card details. Written notification letters began mailing on August 3, 2026.

What Happened

Between March 10 and March 16, 2026, an unauthorized third party accessed one of CareCloud's six AWS electronic health record environments. CareCloud detected the intrusion on March 16 and restored operations that same evening. Third-party cybersecurity investigators confirmed that data had been exfiltrated from that specific AWS account.

CareCloud completed its investigation on June 24, 2026, at which point it confirmed the data types involved. Notification letters to affected individuals began mailing on August 3. The breach was added to the HHS Office for Civil Rights portal on August 18, and detailed coverage followed on August 19–20 from TechCrunch, HIPAA Journal, and SecurityWeek. With 3.75 million individuals affected, this is the fifth-largest confirmed health data theft in the United States in 2026. No known cybercrime group has claimed responsibility, and it is unclear whether a ransom demand was made.

This is not the first time millions of records have been compromised through a third-party provider. We covered a similar exposure earlier this year: the billion-credential infostealer leak, where users had no direct control over the security of data held by a service they trusted.

What Was Stolen

According to CareCloud's breach notifications and the HHS filing, the following data categories were accessed:

  • Personal identifiers — full name, address, date of birth;
  • Government identifiers — Social Security number (SSN), driver's license, passport or government-issued ID number;
  • Medical information — diagnoses, treatment history, health insurance details;
  • Financial information — bank account numbers, credit and debit card numbers.

This is one of the most complete personal data profiles that can be compromised in a single breach. Medical records command some of the highest prices on criminal markets — well above standard identity data. Combined with SSNs, government IDs, and financial account numbers, the risk extends well beyond healthcare: this combination is exactly what enables credit fraud, fake insurance claims, and synthetic identity creation.

Why Medical Data Stays Dangerous for Years

Unlike a compromised password, medical records cannot be "changed." A Social Security number, date of birth, and passport number stay with a person for life. Once this type of dataset falls into the wrong hands, the risk window effectively never closes.

The abuse scenarios are broad: from highly targeted phishing ("your doctor prescribed a new medication — click here to confirm") to credit applications and fraudulent insurance claims filed in your name. Combined breach databases are especially dangerous — if your contacts and SSN surfaced in one incident and your diagnoses in another, an adversary who correlates them holds a near-complete dossier. For how to check whether your data appears in known breach databases, see our privacy blog.

What to Do If You Are Affected

Watch for a notification letter. CareCloud began mailing written notices on August 3, 2026. If you or a family member has been treated at a US clinic or practice that uses CareCloud's EHR software, check your mail.

Freeze your credit. If you have a US SSN, contact Equifax, Experian, and TransUnion and place a credit freeze on your file. It is free, takes minutes, and prevents anyone from opening new credit accounts in your name. You can lift it whenever you need to apply for credit.

Change passwords and enable two-factor authentication. Healthcare portal breaches often come with credential exposure — especially if you reused a password across the patient portal and other accounts. A unique password for each service, stored in a password manager, limits the blast radius of any single compromise.

Stay alert to targeted phishing. Attackers who hold your name, address, and medical history can craft convincing messages from "your doctor" or "your insurance provider." Do not click links in unexpected health-related emails — go directly to the portal or call the clinic.

Encrypt traffic on untrusted networks. A VPN does not undo an already-occurred server-side breach. But when you log into medical portals or online banking over public Wi-Fi, LiMP VPN encrypts your connection and prevents anyone on the same network from intercepting your session credentials. See how it works on the features page.

Sources

CareCloud: 3.7M Patient Records Stolen in AWS Cloud Breach