3.7 Million Patients Had Their SSNs and Medical Records Stolen from a Health Software Company
Your doctor may use CareCloud software. 3.7 million patients just learned hackers stole their SSNs, medical records, and bank details from it back in March.
Your Doctor Used Software You've Never Heard Of. Hackers Found It First.
CareCloud is not an app you downloaded. You never created an account. You never agreed to their terms of service. But if your doctor, specialist, or clinic used their software at any point, CareCloud stored your most sensitive information, and between March 10 and 16, 2026, hackers walked out with it.
That is the part that should make you pause. This was not a breach of an app you chose. This was a breach of infrastructure your healthcare provider chose, on your behalf, without asking you.
What Is CareCloud and Why Does It Have Your Data?
CareCloud is a New Jersey company that sells electronic medical record storage and billing software to tens of thousands of US healthcare providers. When your doctor's office processes your visit, files your insurance claim, or stores your chart, they often use software like this to do it. The records live in CareCloud's systems, not just on your doctor's computer.
Patients never sign up with CareCloud directly. You do not get an account. You do not get a password. You simply exist in their database because your provider put you there. There is no way to opt out. If your doctor uses their software, your data goes there. That is the deal, and no one told you about it.
This model is common across healthcare. Third-party vendors handle billing, records, scheduling, and claims for thousands of practices simultaneously. That efficiency creates massive, concentrated targets.
How the Breach Happened
Between March 10 and 16, 2026, attackers accessed one of CareCloud's AWS cloud environments. They did not just view data. They exfiltrated it, meaning they copied it and took it out.
What they took is a comprehensive identity package. Full names. Home addresses. Social Security numbers. Medical and health records. Passport numbers. Driver's license numbers. Banking and financial information.
Read that list again. That is not just one category of sensitive data. That is every category. A thief with that combination can open credit accounts, file fraudulent tax returns, impersonate you to a healthcare provider, and drain financial accounts. Medical record theft adds another layer: your diagnosis history and treatment records can be used to commit insurance fraud or, in some scenarios, to blackmail.
The Numbers
3,756,469 patients were affected. That makes this the fifth-largest US healthcare data breach of 2026 so far.
CareCloud filed its breach disclosure with the Department of Health and Human Services on August 19, 2026. The breach happened in March. That is more than five months between the incident and the official federal disclosure. Some initial notifications to affected individuals began around July 30, still four and a half months after attackers had already left with the data.
Five months is a long time to be exposed without knowing it.
What to Do Right Now
You do not need to wait for a notification letter to act. If you have visited a doctor, clinic, or specialist in the US at any point, assume your data could be at risk from this breach or others like it. These steps cost nothing and protect you regardless.
-
Freeze your credit at all three bureaus. Go directly to Equifax, Experian, and TransUnion and place a security freeze on your file. This blocks anyone, including you, from opening new credit in your name without first lifting the freeze. It is free. It is the single most effective thing you can do against identity theft.
-
Check your credit reports now. You can access all three reports at no cost. Look for accounts you do not recognize, addresses you have never lived at, or inquiries from companies you did not contact.
-
Monitor your health insurance explanation of benefits. If someone files a fraudulent medical claim using your information, your insurer will send you a summary. Read those statements when they arrive. Flag anything unfamiliar immediately.
-
Place a fraud alert if you cannot freeze. A fraud alert is less protective than a freeze but still prompts lenders to verify your identity before extending credit. One bureau must share it with the others, so you only need to place it once.
-
Watch for phishing that uses your real information. Attackers who buy this data will know your name, address, and possibly your medical history. They will use those details to make scam calls and emails look legitimate. A message that knows your doctor's name and your last appointment date is not proof it is real.
-
Consider an IRS Identity Protection PIN. This is a six-digit number the IRS issues to protect your Social Security number from being used to file a fraudulent tax return. You can sign up through the IRS website.
-
Do not wait for a notification letter to act. By the time mail arrives, months have already passed.
The Systemic Truth
Here is the thing that does not get said enough. Individual vigilance is necessary but not sufficient. You can freeze your credit and monitor your statements, and you should. But you had no role in this breach. You made no decision that exposed you. Your doctor picked the software, your data went to a vendor you never knew existed, and hackers found the vendor before the vendor found the problem.
Healthcare data is extraordinarily valuable and extraordinarily concentrated. The industry's reliance on third-party vendors means one successful attack can affect millions of people across thousands of separate practices. The patients in this breach did not make a risky choice. They went to the doctor.
Until vendors face faster disclosure requirements, stronger security mandates, and real accountability for the data they hold on people who never agreed to their custody, breaches like this will keep happening at this scale.
Do this now:
- Freeze credit at Equifax, Experian, and TransUnion (free, takes minutes each)
- Pull your credit reports and scan for unfamiliar accounts
- Review recent health insurance statements for claims you do not recognize
- Sign up for an IRS Identity Protection PIN
- Be skeptical of any contact that references your personal or medical details
Sources
Common Questions About Breach
What should I do immediately after a data breach?
Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.
How long do companies have to notify me after a data breach?
In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.
Should I freeze my credit after a data breach?
Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.
More in breach
Stay invisible. Follow @hack_decoded