CareCloud data breach (2026): was your email exposed?
CareCloud, a medical billing and health-records company, told more than 345,000 people that an intruder reached one of its cloud environments in March 2026 and took files containing their medical, identity and in some cases financial details. The first notification wave covered just over 345,000 people, and the company later reported 3,756,469 to the US Department of Health and Human Services on August 19, 2026. Check whether your email was caught up in it — and lock down your accounts before the data is misused.
See which breaches hold my email — free →This incident is known from CareCloud’s own notice and regulatory filings, not from a set of leaked records that anyone can search. The data was taken, but it hasn’t been published — so no breach-checking tool, ours included, can tell you whether you were in it. The letter is the answer: if one arrived, treat yourself as affected. A free check is still worth running for a different reason — it shows which other breaches already hold your email.
Figures come from the company's notice, state attorney-general filings and its report to the federal health regulator, not from a leaked record set. Source: CareCloud breach notice and state attorney-general filings, July 2026, and the company's August 2026 report to the US Department of Health and Human Services; reporting by security and healthcare press.
The number changed in August, and it changed by a lot. The first wave of letters, sent from the start of July, went to just over 345,000 people, and that was the figure in the state attorney-general filings. On August 19, 2026 the company reported 3,756,469 people to the US Department of Health and Human Services, and TechCrunch, BleepingComputer, SecurityWeek and The Record all carried the revised total the same day. Nothing about the incident itself moved: the intrusion is still dated to a week in March 2026, and the categories of data are the same. What grew is the count of people the review found inside the stolen files, which is what usually happens when one billing contractor holds records for hundreds of separate medical practices - every practice has to be identified before its patients can be written to. So a letter that has not arrived yet is not an all-clear. The rollout has been running in waves for six weeks, and the revision means it is not finished.
CareCloud's report to the US Department of Health and Human Services, covered on August 19, 2026 by TechCrunch, BleepingComputer, SecurityWeek and The Record
What happened in the CareCloud breach?
CareCloud handles billing and electronic health records for medical practices, which is why most people affected have never heard of the company — the letter arrives because of a doctor's office, not because you signed up for anything. According to the company's notice, an unauthorized party had access to one of its cloud environments between March 10 and March 16, 2026, and claimed to have taken data from databases inside it. The disruption was spotted on March 16; the forensic review that confirmed personal data was actually involved finished on June 24, and notification letters followed from the start of July.
The scale has been revised once already. Filings with state attorneys general in July put it at least 345,000 people, with the largest group - over 270,000 - in Texas. On August 19, 2026 the company reported 3,756,469 people to the US Department of Health and Human Services, which is where healthcare breaches are counted, and the security press picked the figure up the same day. Neither number comes from a published file of records; both come from paperwork filed as the review worked through one medical practice after another, and that is exactly why the count moved.
What makes this one heavier than an average breach is the mix of data. The company listed names, addresses, dates of birth, Social Security numbers, driver's licence and other government ID numbers, financial account and card numbers, and medical and health-insurance information. A Social Security number and a date of birth together are the raw material for opening credit in someone's name, and unlike a password, neither can be changed.
Affected people were offered two years of identity-protection monitoring in the notification letter. Monitoring tells you after something has already been opened in your name, so it is worth taking, but it is not the same protection as freezing your credit file — that is the step that actually blocks new accounts.
What data was exposed in the CareCloud breach?
The CareCloud breach exposed names, physical addresses, dates of birth, social security numbers, government id numbers, financial account numbers, credit card details, medical records and health insurance information. The more of these are tied to you, the more ways an attacker can impersonate you or break into your other accounts.
How the leaked CareCloud data can be used against you
Because the CareCloud breach exposed names, physical addresses, dates of birth, social security numbers, government id numbers and financial account numbers and more, an exposed government ID number is the most dangerous of all, enabling full identity theft; exposed payment details raise the risk of fraudulent charges; your address can be used to locate you, sold on to people-search sites, or used in doxxing; and exposed medical and insurance details enable medical identity theft — treatment or prescriptions billed in your name — and make health-themed scam calls far more convincing.
How to check if you were affected
For this one, the notification letter is the only confirmation there is — nothing about it is searchable yet. If you got a letter, use only the contact details printed on it, because scam waves follow every notification rollout. What you can check right now is the rest of your exposure: which known breaches already hold your email, and what leaked in them.
Check my email against known breaches — free →What to do if your CareCloud account was breached
These steps are prioritized for exactly the kind of data the CareCloud breach exposed.
Add 2FA — ideally an authenticator app or a passkey rather than SMS — to your email, banking and other important accounts, so a stolen password alone can’t get in.
Check bank and card statements for charges you don’t recognize, set up transaction alerts, and ask your bank to reissue any card that may have been exposed.
A government ID number is high-risk. Consider a credit freeze with the major bureaus so no one can open credit in your name, and turn on identity monitoring.
Exposed addresses spread to people-search sites that anyone can look up. Opting out of data brokers makes your home harder to find and lowers your doxxing risk.
Health data misuse shows up as care you never received: a bill, an explanation-of-benefits letter, or a claim on your policy for a treatment that isn’t yours. Read those statements instead of filing them, and query anything unfamiliar with the provider and your insurer — medical identity theft is usually caught this way rather than by credit monitoring.
Leaked data is resold for years, so a one-time clean-up isn’t enough. Ongoing breach and dark-web monitoring tells you the moment your details reappear, so you can act before an account is misused.
Medical records breached? What to do
Health data has no reset button and no bureau to freeze it at, so the steps differ from a normal breach: read the claims your insurer processes, ask each provider for a copy of your record, and query care you never received.
Read the guide →The CareCloud breach, answered
Was I affected by the CareCloud breach?
The notification letter is the only confirmation. Nothing from this incident has been published as a searchable set of records, so no breach-checking tool can answer it for you — including ours. If a letter reached you, treat yourself as affected and act on it; if none did, there is nothing to check yet.
Is the CareCloud breach letter I received genuine?
Letters from a real notification rollout do arrive by post and can look alarming. Verify it the safe way: use only the phone number or web address printed on the letter itself, typed in by hand — never a link in an email or text about the breach. Notification waves are followed by scams that copy the wording of the real letter.
How many people were affected by the CareCloud breach?
The first notification wave covered just over 345,000 people, and the company later reported 3,756,469 to the US Department of Health and Human Services on August 19, 2026. Figures come from the company's notice, state attorney-general filings and its report to the federal health regulator, not from a leaked record set.
What data was exposed in the CareCloud breach?
Per the disclosure, the data included names, physical addresses, dates of birth, social security numbers, government id numbers, financial account numbers, credit card details, medical records and health insurance information. The first notification wave covered just over 345,000 people, and the company later reported 3,756,469 to the US Department of Health and Human Services on August 19, 2026.
What should I do after the CareCloud breach?
Freeze your credit file with all three bureaus — it is free and, unlike monitoring, it blocks new accounts rather than reporting them afterwards. Take the identity-protection offer in the letter as well, watch medical bills and insurance statements for care you did not receive, and expect phishing that references this breach by name.
When did the CareCloud breach happen?
The incident is dated March 2026 and became public in July 2026 (scope revised August 2026). Source: CareCloud breach notice and state attorney-general filings, July 2026, and the company's August 2026 report to the US Department of Health and Human Services; reporting by security and healthcare press.
Is there compensation for this breach?
Breaches this size often end in a class action, and a settlement can take a year or more to reach a claim form. If one opens for CareCloud, it will be run by a court-appointed administrator and announced on the company’s own breach page — never through an unsolicited email asking you to confirm bank details. Our guide to breach settlement claims covers who qualifies, what a payout actually covers, and the deadlines that decide it, and the list of settlements taking claims now is checked against the administrators rather than copied off aggregators.
Was your email in the CareCloud breach?
Check free in about a minute — then we’ll help you remove your exposed data and keep it monitored.
Run my free breach check →