Home Cybersecurity Article

CareCloud Confirms 3.75M Patient Records Stolen in AWS Breach

TL;DR

Healthcare data giant CareCloud disclosed a March breach affecting 3.75 million patients' medical records and financial data via compromised AWS account.

Key Points

  • 3.75 million patients affected—fifth-largest healthcare data breach of 2026
  • Hackers accessed AWS cloud storage environment for six days in March
  • Stolen data includes SSNs, medical records, government IDs, and banking information
  • Company has not disclosed security leadership, breach response, or ransom details

Why It Matters

This incident exposes critical gaps in healthcare infrastructure security and AWS account management at scale. For DevOps and security teams, it highlights the risks of inadequate cloud access controls and the need for robust monitoring of data exfiltration—particularly when handling sensitive PII and PHI across multi-tenant cloud environments.
Full incident details on TechCrunch

Source: techcrunch.com