Healthcare data breach exposes 3.75M patient records


Hackers stole medical records, Social Security numbers, government IDs and financial data from millions of CareCloud patients

You can be careful with your passwords and still get caught in a breach at a company you may have never heard of. That is one of the frustrating parts of the CareCloud data breach. More than 3.75 million people had personal information and medical records stolen after hackers gained access to a CareCloud cloud environment earlier this year.

CareCloud provides electronic medical record technology and other services to tens of thousands of healthcare providers across the U.S. So, even if you never created a CareCloud account, a doctor’s office or another healthcare provider could have used its technology to handle your information. Now, we are getting a much clearer picture of just how much information hackers took.

Read more…
Source:  Fox News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Top US hedge funds targeted by major vishing campaign

    August 9, 2026

    Some of the biggest US hedge funds and law firms have been targeted by a highly sophisticated data breach and extortion campaign, conducted by a group of criminals previously known as BlackFile, experts have warned. BlackFile (or Redact, as the group is now calling itself) has a relatively simple modus operandi, also used by ShinyHunters – ...

  • Intrusion at US healthcare software provider puts 3.8M people’s data at risk

    August 7, 2026

    A US healthcare software provider has admitted that hackers may have made off with sensitive data belonging to 3.8 million people, making it the largest healthcare breach reported to regulators so far this year. The attack dates to last October, when Ohio-based medical software maker Unlimited Technology Systems (UTS) detected someone poking around its commercial datacenter. ...

  • Feds get 3 days to patch N-able God mode flaw under active exploit

    August 4, 2026

    The US Cybersecurity and Infrastructure Security Agency (CISA) has added an exploited N-able vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies three days to patch a flaw that could let attackers reach managed service provider (MSP) customers. Attackers exploiting the flaw can gain “full administrative access to an N-central console,” Tracked as CVE-2026-18577 (8.2 ...

  • FBI: Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers

    July 31, 2026

    North Korea relies upon a network of skilled Information Technology (IT) workers, deployed within and outside of North Korea, to obtain false identities and remotely earn income to fund North Korea’s unlawful nuclear weapons and ballistic missile programs. North Korean IT workers impersonate nationals of other countries to obtain work and income through online platforms operated ...

  • Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems

    July 29, 2026

    Security researchers at Tenable suspect the Iran-linked faux hacktivist outfit CyberAv3ngers was behind the cyberattack that disrupted more than 30 Minnesota water facilities. Neither state-level nor federal officials have made any claims regarding attribution for the attacks, however, Tenable reckons the operational pattern is consistent with the crew’s previous raids, noting the timing relative to recent government warnings. The ...

  • U.S. accuses American of allegedly wiping his phone using a ‘duress’ password during border search

    July 24, 2026

    The U.S. Justice Department is prosecuting an American for allegedly providing U.S. border authorities with a passcode that wiped the contents of his phone, according to an indictment and media reports. This is thought to be the first known case in the United States where federal prosecutors have charged someone for the alleged destruction of data ...