CareCloud leaks 350,000 medical records

Article by Nacata Security, 03/08/2026

Do you trust that your medical records are safe in your doctor’s hands?

CareCloud was compromised in March, and nearly 350,000 people are paying the price.

CareCloud is not a clinic: it is the platform that manages records and billing for more than 45,000 medical practices across the United States.

When someone breaches CareCloud, they don’t steal one record — they steal all of them at once. Every connected physician becomes a collateral victim without having chosen to be.

Metaphorical representation of the compromised cloud environment: medical and financial data escaping from cloud servers
Data with no way back

Six days. That’s all it took.

Between March 10 and 16, 2026, an unknown attacker accessed the Amazon Web Services environment where CareCloud stores electronic health records. The company confirmed that the third party claims to have exfiltrated data from multiple databases. CareCloud took four months to notify those affected, and only did so after pressure from states demanding formal disclosure documents.

They walked away with the perfect combination for fraud.

The exposed data includes full names, postal addresses, Social Security numbers, passport and driver’s license numbers, bank account details, credit card numbers, and detailed medical information. It is exactly the mix that both identity thieves and medical insurance fraudsters look for: with that data, someone can fully impersonate a person — financially and medically — from start to finish.

Nearly 350,000 confirmed victims, and the number has not stopped growing.

The number of confirmed victims is around 350,000, but that figure is not yet final: it continues to rise as more states receive and process the notification filings. CareCloud has not published technical details on how the breach occurred, and no one has publicly claimed responsibility for the attack.

Image of the systemic pattern: a central technology vendor compromised, dragging down thousands of connected practices
Healthcare domino effect

This case is not an exception — it is the pattern.

The healthcare sector consolidates medical, financial, and identifying data in a single location, making it a primary target.

A single compromised technology vendor multiplies the damage exponentially across thousands of clinics.

The breach at TriZetto Provider Solutions affected 3.4 million people in March 2026; shortly after, Craneware confirmed a massive data theft.

The digital healthcare system has a massive crack in it.

Every time a healthcare technology vendor falls, the consequences branch out to thousands of practices and millions of patients who never chose to entrust their data to that company. And the most disturbing part is what comes next.

Four months of silence before any warning.

CareCloud acknowledged the breach in March, but the details took months to come to light. It was California’s disclosure regulations that forced a formal notice to the state attorney general, revealing the true scope of the incident. Without that law, those affected would still be in the dark. This pattern of delayed notification repeats itself in the U.S. healthcare sector time and again.

State laws are the only real check right now.

In the absence of robust federal regulations requiring breach notification within short timeframes, it is the states that fill that gap. California leads with its disclosure requirements, but the protection you receive depends on the state where you live, creating a deep inequality among the very citizens affected.

Metaphor for delayed notification: time runs out while data leaks and only regulatory pressure forces transparency
Silence that causes harm

Your medical records are worth more than your credit card.

On the black market, a complete medical record can be worth ten times more than credit card data, because it enables fraud for years: filing insurance claims, forging prescriptions, or impersonating medical identities in ways the victim is unlikely to detect easily.

And you cannot change your medical history.

Unlike a password, medical data and identifiers such as Social Security numbers are permanent. Once exposed, the damage extends for years. There is no way to reset your medical record, and that makes this type of breach one of the most difficult to manage.

The real damage arrives much later.

Victims of medical breaches typically discover the fraud months or years after the attack, by which point it is far more difficult to trace the origin and reverse the damage caused.

What you can do

  • Review your bank and health insurance statements carefully.
  • Request a credit freeze if you may be affected.
  • If you receive a letter from CareCloud, act immediately.

Do you actually know who is holding your medical data right now?

Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.

Related articles

Nacata Security, reach out to us anytime

How would you rate this news?

We are Nacata Security, get to know us

web: nacata.io

email: info@nacata.io

Phone: 919930793

LinkedIn: Nacata Security

Incidents

Cyberattacks that have already happened and are confirmed: hacked companies, leaked data, services down after an attack, ransoms paid.

Real cases, with names and clear consequences, explained simply so anyone understands what happened and who it affected.



RATING


8.7



Who are we?


At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.


We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.


We’d be glad to get in touch with you for whatever you need.