TL;DR
Healthcare data giant CareCloud disclosed a March breach affecting 3.75 million patients' medical records and financial data via compromised AWS account.
Key Points
- 3.75 million patients affected—fifth-largest healthcare data breach of 2026
- Hackers accessed AWS cloud storage environment for six days in March
- Stolen data includes SSNs, medical records, government IDs, and banking information
- Company has not disclosed security leadership, breach response, or ransom details
Why It Matters
This incident exposes critical gaps in healthcare infrastructure security and AWS account management at scale. For DevOps and security teams, it highlights the risks of inadequate cloud access controls and the need for robust monitoring of data exfiltration—particularly when handling sensitive PII and PHI across multi-tenant cloud environments.
Source: techcrunch.com