{"id":405075,"date":"2026-08-24T04:47:02","date_gmt":"2026-08-24T04:47:02","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=405075"},"modified":"2026-08-24T05:11:59","modified_gmt":"2026-08-24T05:11:59","slug":"carecloud-breach-3-76-million","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/carecloud-breach-3-76-million\/","title":{"rendered":"CareCloud says 3.7 million patient records were stolen. Freeze credit"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">CareCloud told patients that roughly 3.76 million records were caught up in a spring intrusion into one AWS electronic health record environment. Names, Social Security numbers, medical details, and financial data are in the mix depending on the letter you received. If your clinic uses CareCloud, treat this like an identity event, not a software update. Freeze credit at Equifax, Experian, and TransUnion, enroll in IDX only with the code from your own notice, and watch Explanation of Benefits statements for care you did not receive.<\/p><div id=\"mwtad3880128908\" class=\"gas_fallback-ad_309684--placement_400588\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-carecloud-overview-v2.png\" alt=\"Kitchen table with opened CareCloud data breach notice letter, credit freeze checklist, and laptop showing credit bureau freeze page\" class=\"wp-image-405145\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-carecloud-overview-v2.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-carecloud-overview-v2-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-carecloud-overview-v2-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><figcaption class=\"wp-element-caption\">The letter is your enrollment door.<\/figcaption><\/figure>\n\n\n\n<div id=\"mwtad2287608712\" class=\"gas_fallback-ad_309747-ad_309691-placement_400589\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What broke<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">CareCloud is a healthcare technology company that provides electronic health records and related clinical tools to medical practices. You may never have typed CareCloud into a browser and still be in range if your doctor, dentist, or specialist runs on their platform.<\/p>\n\n\n\n<div id=\"mwtad2189926145\" class=\"mwtadp1 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"> \r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"7312657698\"><\/ins>\r\n <\/div><p class=\"wp-block-paragraph\">According to the sample notice filed with the <a href=\"https:\/\/oag.ca.gov\/ecrime\/databreach\/reports\/sb24-627090\" target=\"_blank\" rel=\"noopener\">California Attorney General for CareCloud<\/a>, the company saw a network disruption on 16 March 2026 in its CareCloud Health division. The investigation found that between 10 March and 16 March 2026 an unauthorized party accessed one AWS environment and claimed to have taken data from databases there. CareCloud says it found no evidence of unauthorized activity in that environment after 16 March 2026.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By late June the company had narrowed what may have been involved for each person. The letter template says affected data may include full name plus one or more elements listed for that individual. Reporting around 18 and 19 August 2026 put the HHS-scale patient count near 3,756,469. Treat that figure as the breach scale, not a guarantee your clinic was or was not included. Your letter is the personal proof.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Who is in range<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You. Patients of practices that used the affected CareCloud EHR environment. You do not need a CareCloud login. You need a relationship with a provider who stored your chart there.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you received a mailed or emailed CareCloud notice, you are in range. If your clinic sent its own letter naming CareCloud, you are in range. If you only saw a headline and never got mail, call the clinic billing office and ask whether they sent notices for this incident before you assume you are clear.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What the vendor shipped<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Containment and forensics after the March disruption, with a claim of no ongoing unauthorized access after 16 March 2026.<\/li>\n<li>Individual notices that offer IDX identity protection: credit and CyberScan monitoring for 12 or 24 months as printed on your letter, $1,000,000 insurance reimbursement, and ID recovery help.<\/li>\n<li>Enrollment through IDX at their protect signup page, phone (866) 329-9984, Monday through Friday 9 a.m. to 9 p.m. Eastern, deadline 17 December 2026.<\/li>\n<li>Guidance in the same letter to place fraud alerts or security freezes at Equifax, Experian, and TransUnion, and to review medical Explanation of Benefits statements.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">There is no app update for you to click. The work is identity hygiene using the official notice.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What this is not<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Not a reason to invent an enrollment code from a blog comment or a text message. Codes come from your letter only.<\/li>\n<li>Not proof that every patient of every CareCloud customer is affected. Scope follows the AWS EHR environment named in the notice.<\/li>\n<li>Not fixed by changing your clinic patient-portal password alone, though you should still use a unique password there.<\/li>\n<li>Not a green light to ignore credit freezes because IDX monitoring exists. Freezes and monitoring do different jobs.<\/li>\n<li>Not medical advice. It is a consumer checklist for a documented breach notice.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The California AG sample notice and your own letter are the primary papers. Use them.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-carecloud-house.png\" alt=\"Do This Now card: Freeze credit and enroll IDX from your letter, in range You, urgency Today, then Equifax Experian TransUnion\" class=\"wp-image-405074\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-carecloud-house.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-carecloud-house-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-carecloud-house-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><figcaption class=\"wp-element-caption\">Freeze credit. Use your letter for IDX.<\/figcaption><\/figure>\n\n\n\n<div id=\"mwtad3785763229\" class=\"gas_fallback-ad_309748-ad_309691-placement_400590\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Do This Now<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>In range:<\/strong> You. Patients tied to the CareCloud EHR incident, especially anyone with a notice letter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Urgency:<\/strong> Today. SSN-class and medical data make delayed freezes expensive.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Place a free security freeze at Equifax, Experian, and TransUnion online. Save the PINs they email or mail you.<\/li>\n<li>If your CareCloud or clinic letter offers IDX, enroll at the IDX protect signup page or by calling (866) 329-9984 using only the Enrollment Code printed on your letter before 17 December 2026.<\/li>\n<li>Watch bank statements, credit reports, IRS accounts (consider an IRS IP PIN), and health Explanation of Benefits for care or claims you do not recognize.<\/li>\n<\/ol>\n\n\n\n<div id=\"mwtad1871370043\" class=\"gas_fallback-ad_309749-ad_309691-placement_400591\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5354318971\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Who can skip<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You confirmed with your clinic that they did not use the affected CareCloud environment and you received no notice.<\/li>\n<li>You already froze all three bureaus after this letter, enrolled IDX with your real code, and set calendar reminders to review EOBs.<\/li>\n<li>You are not a U.S. patient in this incident scope (follow your local notice if you received a different regional letter).<\/li>\n<\/ul>\n\n\n\n<div id=\"mwtad1264276517\" class=\"gas_fallback-ad_309750-ad_309691-placement_400592\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4041237300\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Why it matters<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Medical breaches combine identity theft with insurance fraud. Someone with your SSN and clinical details can open credit and file claims that only show up when a collection call arrives or a pharmacy rejects a script.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Credit freezes stop most new-account fraud cold. Monitoring tells you after something wobbles. You want both when SSN is in play. IDX is useful only if you enroll with the code CareCloud actually issued you. Random codes from strangers are how secondary scams start.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CareCloud states it is not aware of identity fraud tied directly to this incident as of the letter language. That sentence is not a promise the data will never be misused later. Freezes are cheap. Leaving credit open for convenience is how spring medical data becomes winter loan applications.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Household tip: freeze credit for minors in the family if their data could have been in a pediatric chart. Child freezes follow bureau rules for protected consumers. Do that from the same official freeze pages, not from a random &#8220;child credit lock&#8221; ad.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Phishing wave watch: after big health breaches, fake &#8220;CareCloud billing&#8221; and &#8220;IDX support&#8221; emails show up. Real enrollment uses the letter code and the IDX domain printed in the notice. Real clinic bills come through channels you already use. When in doubt, call the number on your insurance card or the response line printed on the CareCloud letter, not a number inside a fresh email.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you already froze your credit after an earlier breach this year, log into each bureau and confirm the freeze is still active. Freezes do not expire the way some fraud alerts do, but people sometimes lift them for a car loan and forget to turn them back on.<\/p>\n\n\n\n\n<div id=\"mwtad1547405784\" class=\"gas_fallback-ad_309751-ad_309691-placement_400593\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3690286463\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">The bottom line<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Freeze the three bureaus<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>On a trusted computer, open Equifax credit freeze, Experian freeze, and TransUnion credit freeze pages from the official bureau sites (linked from the CareCloud notice).<\/li>\n<li>Complete each freeze. You will need identity details matching your credit file.<\/li>\n<li>Store each PIN or password in your password manager. You need them to lift a freeze when you apply for credit later.<\/li>\n<li>Optionally place a fraud alert with one bureau; they notify the others. A freeze is still the stronger default.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Enroll IDX from your letter only<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Find the Enrollment Code and the 17 December 2026 deadline on your notice.<\/li>\n<li>Go to the IDX account-creation protect page printed in the letter, or call (866) 329-9984 on weekdays 9 a.m. to 9 p.m. Eastern.<\/li>\n<li>Enter the code from the letter. Activate credit monitoring inside IDX after you join so monitoring is actually on.<\/li>\n<li>Ignore texts, DMs, or ads that ask for the code or demand payment to &#8220;unlock CareCloud protection.&#8221;<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Medical and tax watch<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Read every Explanation of Benefits. Call the insurer about visits, labs, or equipment you do not recognize.<\/li>\n<li>Ask your insurer for a year-to-date claims summary if EOBs are hard to track.<\/li>\n<li>Consider an IRS IP PIN so a thief cannot file a tax return as you as easily.<\/li>\n<li>Pull free annual credit reports on a staggered schedule from AnnualCreditReport.<\/li>\n<\/ol>\n\n\n\n\n<h3 class=\"wp-block-heading\">If you never got a letter<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Call the clinic where you were seen in the months before March 2026 and ask whether they sent CareCloud notices. Ask how they will verify your identity on that call before they discuss your chart. If they confirm you are in scope, ask them to resend the notice or give you the official enrollment path in writing. Do not accept a verbal enrollment code over a cold call that you did not place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Keep the paper letter or a PDF scan. You may need the Communication Reference Number and Enrollment Code months later if IDX support asks for them. Shredding the letter after one glance is how people lose the only legitimate code they will get.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What you should see<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Each bureau confirms a freeze is active. IDX sends an enrollment confirmation tied to your letter code. Your clinic portal still uses a password only you set. No one should demand remote access software to &#8220;finish CareCloud enrollment.&#8221;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">When you are done<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Three freezes are on. IDX is enrolled from your letter if you received an offer. EOB and credit-report checks are on your calendar. You did not invent a code. You used the California AG-backed notice path and your own mail. That is the job.<\/p>\n\n<div id=\"mwtad3564654471\" class=\"gas_fallback-ad_176819-ad_309691-placement_400595\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>CareCloud told patients that roughly 3.76 million records were caught up in a spring intrusion into one AWS electronic health record environment. Names, Social Security numbers, medical details, and financial data are in the mix &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"CareCloud says 3.7 million patient records were stolen. Freeze credit\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/carecloud-breach-3-76-million\/#more-405075\" aria-label=\"Read more about CareCloud says 3.7 million patient records were stolen. Freeze credit\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":405145,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3605],"tags":[],"class_list":["post-405075","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/405075","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=405075"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/405075\/revisions"}],"predecessor-version":[{"id":405146,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/405075\/revisions\/405146"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/405145"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=405075"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=405075"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=405075"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}