A healthcare data breach that went largely unnoticed in March has now affected more than 3.75 million people. CareCloud, a company managing patient records for medical billing, disclosed the expanded scope in August after updating federal health authorities about unauthorized access to its database systems.
The breach occurred between March 10 and March 16 this year when someone accessed CareCloud’s Amazon Web Services database without permission. The company initially reported 345,000 affected individuals when filing with the Securities and Exchange Commission. The number of potentially affected individuals later reported to the U.S. Department of Health and Human Services was 3,756,469.
CareCloud informed the Securities and Exchange Commission about temporary operational disruptions on March 24, 2026, through standard corporate filing procedures. However, the full scale of the data exposure remained unclear for months. When the company updated its formal notice to the U.S. Department of Health and Human Services in August, the scope expanded significantly—a tenfold increase from the initial estimate.
Breach notices indicate exposure of personal, financial and medical information including names, dates of birth, Social Security numbers, and insurance information. Medical data attracts criminal attention because it combines personal identity information with payment details and healthcare history, making it valuable for fraudulent applications and identity theft.
CareCloud responded by isolating the affected database environment and brought in third-party specialists to investigate how the breach happened. The company’s remediation included identity protection and credit monitoring services for affected individuals.
Healthcare organizations handle sensitive information about millions of Americans daily. Data security in the medical field matters because compromised records can affect people’s insurance coverage, credit scores, and ability to access legitimate medical care.