CareCloud confirms 3.7M patients had their medical records stolen in data breach


Hackers have stolen the personal information and medical records of more than 3.75 million people in a data breach at health data giant CareCloud, the company has confirmed with federal regulators. The disclosure marks the first confirmation of the scale of the data breach, which is now confirmed to be the fifth-largest theft of health data in 2026 so far.

CareCloud detailed the March data breach in a filing with the Department of Health and Human Services (HHS) on Monday. The number of affected victims was reportedly revised up in an update on Tuesday, though it’s unclear if the figure is expected to rise further.

Read more…
Source:  TechCrunch News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • US charges Chinese hackers who allegedly caused millions of dollars worth of damages

    March 5, 2025

    US prosecutors on Wednesday announced criminal charges against multiple Chinese nationals for allegedly hacking a range of US companies and municipalities for profit, causing millions of dollars’ worth of damage. Victims of the hackers include US-based critics of the Chinese government, Asian government foreign ministries, and US federal and state agencies, the Justice Department said. Some ...

  • US suspends offensive cyber operations against Russia

    March 3, 2025

    The US has suspended operations and planning for offensive cyber operations against Russia, a senior US official told CNN. The suspension is “a major blow,” the official said, especially since planning for such operations takes time and research to carry out. The concern, the official said, is that the pause on offensive cyber operations against Russia ...

  • British nationals told they could be banned or deported from US amid censorship row

    March 1, 2025

    British nationals have been told that they could be banned or deported from the US as the free speech row rages on across the transatlantic. US Congressman and chair of the House Judiciary Committee, Jim Jordan, handed a letter to Keir Starmer slamming the state of UK “censorship”. He added that his committee had subpoenaed American ...

  • Cyber Attack Keeps Cleveland Municipal Court Offline

    February 28, 2025

    Cleveland Municipal Court will remain closed Thursday, four days after officials announced a cyber attack against the court. The court has been closed since Monday. All internal systems and software, including the court’s website, have been shut down and will remain offline as authorities work to figure out what happened and the best time to restore ...

  • How hackers ruined a Disney employee’s life after he downloaded AI photo tool

    February 27, 2025

    A former Disney employee’s world was turned upside down when he downloaded an artificial intelligence-powered photo program, unaware that it was laced with hacking software, during a massive data breach at the entertainment giant. In July, Matthew Van Andel, an engineer at Disney at the time, got a message on the chat forum Discord from an ...

  • New York amends data breach law

    February 24, 2025

    On December 24, New York Gov. Kathy Hochul (D) signed into law an amendment to section 899-aa of the N.Y. General Business Law, also known as The Shield Act, modifying the law’s data breach notification requirements. The amendment, which took effect immediately, incorporates provisions that other states have adopted in recent years. First, the amendment shortens ...