Security News

CareCloud Data Breach Now Affects 3.7 Million People, Far More Than First Reported

Security Week · 19 Aug 2026
Key Takeaway Regularly review what data your third-party providers hold about your customers, and ask how quickly and transparently they would notify you in the event of a breach.

Healthcare technology provider CareCloud has revised the scale of a data breach dramatically upward, from an initial estimate of roughly 350,000 affected individuals to 3.7 million, based on figures reported to the US Department of Health and Human Services (HHS) breach tracker.

The sharp increase highlights how the true scope of a breach can take time to emerge, as organisations continue investigating affected systems and records long after initial disclosure. For businesses that handle sensitive personal or health data, this case is a reminder that breach impact assessments are often revised as more information comes to light.

While CareCloud operates in the US healthcare sector, Australian small businesses that store customer or patient data, whether directly or through third-party vendors, should take note. Data breaches involving service providers can expose far more information than initially assumed, and businesses relying on external platforms should understand what data those providers hold and how breaches are reported.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.