CareCloud confirms 3.7M patients had their medical records stolen in data breach


Hackers have stolen the personal information and medical records of more than 3.75 million people in a data breach at health data giant CareCloud, the company has confirmed with federal regulators. The disclosure marks the first confirmation of the scale of the data breach, which is now confirmed to be the fifth-largest theft of health data in 2026 so far.

CareCloud detailed the March data breach in a filing with the Department of Health and Human Services (HHS) on Monday. The number of affected victims was reportedly revised up in an update on Tuesday, though it’s unclear if the figure is expected to rise further.

Read more…
Source:  TechCrunch News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Amazon Web Services data centres in the Middle East hit by Iran strikes

    March 3, 2026

    Amazon Inc has said two Amazon Web Services data centres in the United Arab Emirates were hit by drone strikes, with another facility in Bahrain damaged by a nearby attack, as Iran retaliated to the strikes by the US and Israel. AWS said the strikes caused “structural damage” and “disrupted power” to its infrastructure. It warned ...

  • Hacked traffic cams and hijacked TVs: How cyber operations supported the war against Iran

    March 3, 2026

    On Saturday, U.S. and Israeli jets began a bombing campaign against Iran, killing its supreme leader Ali Khamenei and several senior government officials. The attacks also hit military and civilian targets all across the country, including a girls’ school, where at least 168 children and adults were killed. After a few days of conflict, multiple reports, ...

  • LexisNexis hacked, 2 GB of structured data allegedly exposed

    March 3, 2026

    The hacker group FulcrumSec is taking responsibility for a data breach of information from LexisNexis. The group claims to have hacked into the LexisNexis servers on Feb. 24. It posted about the hack and alleged it got access to over 2 gigabytes of structured data. “We exfiltrated 2.04 GB of structured data from LexisNexis AWS infrastructure ...

  • Samsung TVs stop spying on viewers in Texas, here’s how to disable ACR anywhere

    March 2, 2026

    Samsung has settled a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR). As part of the settlement, Samsung agreed to stop collecting ACR data from Texans without explicit, informed consent and to rewrite its on‑screen privacy prompts and dialogs. Read more… Source: Malwarebytes Labs Sign up ...

  • US using cyber warfare to fracture Islamic regime from within its ranks

    March 1, 2026

    The United States is using cyber operations not only to disrupt Iran’s military capabilities but to pressure senior regime officials to defect, a former top commander of US Cyber Command told The Jerusalem Post on Sunday, describing an information warfare campaign aimed at accelerating regime change from within. Using information warfare, Lt. Gen. Charles L. Moore Jr. ...

  • US Military Used Anthropic AI to Crunch Intel and Pick Targets in Iran Strike, Despite Trump’s Ban

    March 1, 2026

    The US military reportedly used Anthropic’s Claude AI during a major strike in the Middle East against Iran, just hours after US President Donald Trump ordered all federal agencies to stop using the technology. According to WSJ, officials say the AI helped with intelligence analysis, spotting potential targets, and running ‘what-if’ battle scenarios. Even though Trump had ...