a healthcare company sat on your stolen medical records for months before telling you

CareCloud confirmed in June that hackers had walked off with your Social Security number and diagnosis history. It didn't start mailing letters…

Aliteq
Priya Nair · Software & Systems Editor

CareCloud is notifying at least 345,000 patients — including 270,197 Texas residents — after a March 2026 breach of one of its six AWS-hosted EHR environments.

Attackers had access between March 10 and March 16, 2026; CareCloud detected the intrusion March 16 after a network disruption and restored the environment within about eight hours.

Confirmation that files were actually exfiltrated didn't come until June 24 — over three months after the intrusion window closed.

Notification letters didn't go out until August 3 — roughly five months after the breach began.

Exposed data includes names, addresses, dates of birth, Social Security numbers, driver's license/ID numbers, financial account and card numbers, and medical and health insurance information.

This is a medical identity theft risk, not just a financial one

A stolen credit card number gets canceled and replaced. A stolen medical record number and diagnosis history doesn't expire — it can be used to file fraudulent insurance claims or obtain care in…

Aliteq

Read the full story

a healthcare company sat on your stolen medical records for months before telling you

Read the full story on Aliteq