💛 A quick favor, if you've got a second.
We're really happy that you chose to read one of our stories and sincerely hope you'll stick around to read more. We took our paywall down — for now — but that won't last forever, and when the gate goes back up, we'd love for you to already be on the inside.
It's free. So please enter your email here and don't forget to like and follow us on all of your favorite Social Media platforms!

A significant cybersecurity incident at CareCloud, which supplies electronic medical record systems to thousands of U.S. healthcare providers, has compromised the personal information and medical records of more than 3.75 million individuals. The breach ranks among the largest healthcare data thefts reported during 2026, according to federal health regulators. Many affected individuals may never have directly interacted with CareCloud, as their information passed through the company’s systems via their healthcare providers.
Unauthorized third parties accessed a CareCloud Amazon Web Services environment between March 10 and March 16, 2026, according to a breach notice filed with the California Attorney General. A network disruption was detected on March 16, prompting CareCloud to engage outside cybersecurity experts for investigation. The company determined that attackers claimed to have extracted data from databases within that environment. No evidence of continued unauthorized access was found after March 16.
Initial disclosures suggested hundreds of thousands of people were affected, but subsequent investigation expanded the figure dramatically. The compromised data extends well beyond basic contact information and includes Social Security numbers, banking details, insurance information, and complete medical histories. The specific data exposed varies among victims, but the combination creates substantial risk for identity theft and fraud.
Medical identity theft presents particular concern in this breach, as criminals could use stolen insurance or personal information to seek healthcare under someone else’s identity. Fraudulent claims may appear on victims’ health insurance accounts, and incorrect medical information could eventually contaminate legitimate medical records. Unlike passwords, medical histories cannot easily be reset or replaced after exposure.
CareCloud has offered complimentary identity protection services through IDX to affected individuals. The company reports having engaged law enforcement and cybersecurity specialists following discovery of the incident. Affected individuals should review notification letters carefully for enrollment instructions and enrollment deadlines for available protection services.
Experts recommend that affected individuals take immediate protective measures including reviewing their medical records and insurance statements for unfamiliar treatments, providers, or charges. Those whose Social Security numbers were exposed should consider placing credit freezes with Equifax, Experian, and TransUnion at no cost. Continuous monitoring of bank accounts, credit cards, and credit reports for suspicious activity remains essential.
Heightened vigilance against phishing attempts is warranted, as criminals now possess sufficient personal and medical information to craft convincing fraudulent messages impersonating healthcare providers, insurers, or breach-response companies. Strong antivirus software and two-factor authentication for critical accounts provide additional protection layers. The Federal Trade Commission’s IdentityTheft.gov website offers resources for reporting suspected identity theft and developing recovery plans.
More Stories
New York Health Officials Sound Alarm Over Rising Measles Cases as School Year Approaches
Month-Long HEPA Use Linked to Faster Cognitive Processing in Middle-Aged Adults
House Republicans Escalate Pressure on New Jersey Governor Over Noncitizen Voter Registration Failure