CareCloud breach total jumps from 345,000 to 3.75 million

A break-in at CareCloud in March looked, for five months, like a mid-sized healthcare incident affecting roughly 345,000 people. The US government's breach tracker now lists the number as 3,756,469.

CareCloud is a New Jersey company that sells electronic health record and practice management software to medical practices, which means it holds patient data on behalf of a long list of providers rather than treating anyone itself. That is why a single intrusion at a single vendor can produce a victim count larger than most hospital systems could reach on their own.

The company first flagged the incident in a filing with the Securities and Exchange Commission in March. An unauthorized third party reached one of CareCloud's Amazon Web Services environments between 10 and 16 March 2026, and the intrusion knocked out one of the company's six electronic health record environments for about eight hours before systems came back the same evening. Neither the original disclosure nor the revised tally explains how the intruder got in, and CareCloud has not named anyone responsible.

Why the count grew tenfold

The jump came from the US Department of Health and Human Services breach portal, where healthcare organizations and the vendors that serve them are required to report incidents involving protected health information. The CareCloud entry moved this month from roughly 345,000 individuals to 3,756,469. Revisions of this kind are routine and they almost always travel in one direction: the first figure is what a company can confirm in the days after an intrusion, and the final one is what a forensic review of the affected databases yields weeks or months later. Researchers at Malwarebytes Labs, who set the two figures side by side, note that the revision makes this one of the largest healthcare data incidents disclosed this year.

Card numbers with the CVV attached

The categories CareCloud lists as involved cover nearly every kind of record a person would not want travelling together: full names, postal addresses and dates of birth; Social Security numbers alongside driver's license or passport numbers; medical records and health insurance information; and bank account and financial details. For a limited subset of people the exposure extends to full credit card data including the CVV, the short code printed on the card that is meant to prove the card is physically in the buyer's hands.

CareCloud's forensic investigation determined that the attacker claimed to have taken data from databases inside the affected environment. That is the intruder's claim rather than a confirmed inventory, and the company has not published one.

It lands in a busy stretch for US data-exposure filings. Consumer lender Heights Finance disclosed a breach involving Social Security numbers and bank details earlier this month, and AssuranceAmerica reported 6.9 million driver's license numbers in July. Our United States profile tracks the wider pattern.

Why this letter deserves a credit freeze

Anyone who receives a notification should treat it as more serious than the average breach letter. Identity documents plus health records plus banking details is the combination that supports both financial fraud and convincing impersonation, and none of it can be reissued the way a password can.

The uncomfortable part of this story is not the size of the number. It is that the number was wrong by a factor of ten for five months, while the people in it had no reason to think they were affected. Patients never chose CareCloud, their doctors did, and the accounting of what was taken from a software supplier arrives on the supplier's timetable.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions