Healthcare data breach exposes 3.75M patient records


Hackers stole medical records, Social Security numbers, government IDs and financial data from millions of CareCloud patients

You can be careful with your passwords and still get caught in a breach at a company you may have never heard of. That is one of the frustrating parts of the CareCloud data breach. More than 3.75 million people had personal information and medical records stolen after hackers gained access to a CareCloud cloud environment earlier this year.

CareCloud provides electronic medical record technology and other services to tens of thousands of healthcare providers across the U.S. So, even if you never created a CareCloud account, a doctor’s office or another healthcare provider could have used its technology to handle your information. Now, we are getting a much clearer picture of just how much information hackers took.

Read more…
Source:  Fox News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • CISA warns max-severity n8n bug is being exploited in the wild

    March 12, 2026

    The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that hackers are exploiting a max-severity remote code execution (RCE) vulnerability in workflow automation platform n8n. CISA urged all federal civilian executive branch (FCEB) agencies to patch CVE-2025-68613 at once because it carries a near-perfect 9.9 vulnerability score. The bug was first disclosed in December, and ...

  • Iran-linked hackers launch cyberattack against U.S. medtech company Stryker

    March 11, 2026

    U.S. medical technology company Stryker is currently experiencing a massive cyberattack, which has shut down their computer systems and, as a result, even closed the company’s offices. An Iran-linked digital activist collective known as Handala is claiming credit for the cyberattack against Stryker. This would be the first major cyberattack carried out in the wake of the ...

  • Ericsson US reveals employee and customer data breach after third-party hack

    March 10, 2026

    The US arm of Ericsson has confirmed suffering a third-party data breach which saw it lose sensitive data on an undisclosed number of its customers. In a data breach notification letter sent out to affected individuals, Ericsson US said it spotted “a suspicious event” and potential unauthorized access to its systems on April 28, 2025. The ...

  • DOGE employee stole Social Security data and put it on a thumb drive

    March 10, 2026

    A former employee of Elon Musk’s Department of Government Efficiency reportedly stole Americans’ personal data from the U.S. Social Security Administration and stored it on a thumb drive, according to a whistleblower complaint reported by The Washington Post. The former DOGE software engineer told co-workers at his new job that he “possessed two tightly restricted databases ...

  • US military contractor likely built iPhone hacking tools used by Russian spies in Ukraine

    March 10, 2026

    A mass hacking campaign targeting iPhone users in Ukraine and China used tools that were likely designed by U.S. military contractor L3Harris, TechCrunch has learned. The tools, which were intended for Western spies, wound up in the hands of various hacking groups, including Russian government spooks and Chinese cybercriminals. Last week, Google revealed that over the ...

  • Salt Typhoon is hacking the world’s phone and internet giants

    March 9, 2026

    Salt Typhoon is behind one of the broadest hacking campaigns in recent years, targeting some of the world’s largest phone and internet companies and stealing tens of millions of phone records about senior government officials. The hacking group, attributed to China, is part of a wider cluster of hackers with the collective aim of helping China ...