CareCloud data breach: what happened to 350,000 patients' medical records

New Jersey-based health technology company CareCloud has confirmed that hackers accessed one of its electronic medical record databases for at least six days — between 10 and 16 March 2026 — according to a notification the company filed with the California Attorney General's office.
CareCloud maintains patient databases for more than 45,000 doctor's offices, hospitals and other medical institutions across the United States, making it one of the country's largest health technology infrastructure providers. Its systems hold highly confidential medical and billing data for millions of patients.
Company representatives said unidentified attackers claimed to have either deleted or copied data from the databases — a statement that leaves some ambiguity about exactly what the attackers did once inside, a common uncertainty in breach disclosures of this kind.
Although the incident occurred in March, notification letters to affected individuals only began going out in July — a timeline that reflects the months typically spent scoping an investigation and compiling a complete list of affected records in healthcare data breaches.
Roughly 350,000 people in total are estimated to have been affected. Healthcare data breaches are considered especially serious because the stolen information often includes highly sensitive, durable data such as Social Security numbers, diagnosis codes, prescription history and insurance details — information that, unlike a credit card number, cannot easily be changed.
The attackers were found to have breached CareCloud's data storage infrastructure hosted on Amazon Web Services. This reflects a common pattern in healthcare-sector attacks, where the cloud infrastructure of major technology providers itself is not compromised; rather, attackers exploit vulnerabilities within a customer account.
No known hacker group or ransomware gang has claimed responsibility for the attack so far, distinguishing it from some high-profile ransomware incidents in which responsibility is publicly announced as a matter of course.
This is not an isolated incident for CareCloud. In late March, the company had already disclosed a separate data access event connected to the same breach, indicating the timeline and full scope of the incident have come into focus gradually over months of investigation.
Cybersecurity experts note that healthcare data infrastructure providers have become centralised enough that a single breach can simultaneously affect thousands of healthcare organisations and millions of patients. That concentration offers attackers a large data payoff from a single target, while also significantly widening the blast radius of any one vulnerability on the defensive side.
Affected individuals are being offered identity theft monitoring services, and security experts recommend that anyone who receives a notification letter closely monitor their credit reports and remain alert to medical identity theft, since stolen medical information can also be misused for fraudulent insurance claims or prescription fraud.
Read next

Google DeepMind unveils Gemini Robotics 2, giving robots 'whole body' intelligence
Google DeepMind announced Gemini Robotics 2 on 30 July, a family of AI models designed to give robots coordinated control of their entire body, from torso to legs. The system achieved a 92% success rate at a task requiring it to unscrew a lightbulb in tests, though success rates dropped to as low as 46% for tasks like picking objects up off the floor.

Quantum advantage: how do we know a quantum computer's results are correct?
Teams including IBM, the University of Chicago, Algorithmiq, Qedma and RIKEN published three separate papers on the same day, 30 July, each claiming to perform calculations beyond the reach of classical computers — this time with built-in verification methods that can confirm the results are accurate. The work tackles the question that has long undermined 'quantum advantage' claims: if you can't check the answer classically, how do you know it's right?

How AI is helping Google find and fix Chrome bugs faster
Google says it fixed 1,072 security bugs across two Chrome releases in June — more than the 1,036 bugs patched over 23 releases in the previous two years. The company credits the jump to AI agents scanning its codebase, including a workflow that surfaced a sandbox-escape vulnerability that had gone unnoticed for 13 years.

Do school phone bans work? What the data shows
A new Pew Research Center survey finds 77% of US adults support banning cellphones in class, and 48% now back all-day bans — up from just 36% two years ago. Here's what's driving the shift in opinion, and what the research actually shows.

Why are AI's top startups publishing less research than ever?
The field of AI, once known for its culture of open research, is entering a more closed era in which the leading startups are sharing their findings less and less. Here's what's driving the shift, and what it means for the wider scientific community.