The CareCloud data breach 3.7 million figure is now 3,756,469 people, according to the healthcare software company’s latest report to the U.S. Department of Health and Human Services. That is the reported scale of a March intrusion involving an Amazon Web Services environment used by CareCloud, which supplies electronic health record and billing systems to healthcare providers.
The total is CareCloud’s submission to HHS, not an independent count of individual records. SecurityWeek reported that HHS confirmed the number reflected the company’s most recent information. The reported figure had previously stood at 3,371,508 on the agency’s tracker, while earlier notices filed with state authorities pointed to roughly 350,000 affected people.
That jump does not establish that the intrusion expanded after discovery. It shows that CareCloud’s estimate of the people affected changed as its investigation and notification process continued.
What happened in the CareCloud data breach?
CareCloud’s notification materials say an unauthorized party accessed one of its AWS environments between March 10 and March 16, 2026, and claimed to have taken data from databases in that environment. The company had disclosed the incident in March after an eight-hour service disruption affected an electronic health record environment, according to The Record.
Access to a cloud environment is not proof that identical information was taken for every affected person. CareCloud’s reported data categories include names and addresses; Social Security numbers and other government identification numbers; insurance and medical information; and financial or payment-card data. SecurityWeek reported that full payment-card information applied only to a very limited subset of people. BleepingComputer said the sample notice provided to authorities specified names but did not list other data categories.
CareCloud began sending breach notices on July 25, BleepingComputer reported. Recipients were offered identity-protection coverage through IDX. Teiss reported that CareCloud said it found no indication that exposed information had been misused, but that statement does not settle whether information was copied, retained, or later misused.
What is still unknown?
- No cybercrime or ransomware group had publicly claimed responsibility in the reporting reviewed by The Record, SecurityWeek and BleepingComputer.
- The available reporting does not identify the attacker or explain the method used to gain access.
- CareCloud has not publicly established the amount of data taken, whether a ransom was demanded or paid, or whether the affected-person count will change again.
HHS says covered entities must report qualifying breaches of unsecured protected health information affecting 500 or more people without unreasonable delay and no later than 60 calendar days after discovery. The department can review a report, seek verification, investigate, refer it elsewhere, provide technical assistance, or close it. A breach report is not, by itself, an agency finding about responsibility.
People receiving a CareCloud notice should be alert to phishing messages that use medical or identity details to look convincing. CareCloud’s guidance, as reported by Teiss, was to review credit reports, account statements and benefits statements for suspicious activity.
This story draws on original reporting from The Record.