What happened
CareCloud, a New Jersey-based company that provides electronic health records and billing services to tens of thousands of healthcare providers, confirmed in an August 19 filing with the Department of Health and Human Services that its data breach affected 3.75 million people. That is roughly ten times the earlier estimate of about 350,000 disclosed when notifications began in July. The intrusion happened in March, when attackers spent about six days inside one of CareCloud's Amazon Web Services environments. The stolen data is unusually comprehensive: names, addresses, dates of birth, Social Security numbers, driver's license and other government ID numbers, financial account and payment card details, and medical and health insurance information. Reporters tracking the incident rank it as the fifth-largest healthcare data theft of 2026 so far, and the company has said little publicly beyond its required notifications.
Why it matters for your business
If you run a medical, dental, or therapy practice in the DMV, this is a vendor-risk story, not just a big-company story. Practices of every size hand patient data to cloud EHR and billing vendors, and when that vendor is breached, the notification obligations, patient anger, and regulatory exposure land on the whole chain. Two details deserve attention. First, the attackers needed less than a week inside a cloud environment to take millions of records, so detection speed matters as much as prevention. Second, the affected-person count grew tenfold over several weeks, a reminder that a vendor's first breach notice is rarely the full picture.
What to do about it
- Inventory which vendors hold your customer or patient data, and confirm you have a signed business associate agreement with each one that touches health information
- Ask your key vendors how they would notify you after a breach and on what timeline
- If your practice uses CareCloud, contact them about whether your patients are affected and prepare notification letters early
- Enable multi-factor authentication and alerting on your own cloud accounts; six quiet days was all this attack needed
