HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

CareCloud Data Breach Exposes Medical Records, SSNs, and Credit‑Card Details of 3.75 Million Patients

CareCloud disclosed that an unauthorized actor accessed its AWS environment in March 2026, exfiltrating personal, medical, and financial data for over 3.75 million individuals. The breach highlights the need for robust privacy controls and continuous audit evidence in SOC 2 programs.

LiveThreat™ Intelligence · 📅 August 22, 2026· 📰 malwarebytes.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Medical Records, SSNs, and Bank Details Exposed in CareCloud Data Breach Affecting 3.75 Million Individuals

What Happened — CareCloud, a provider of electronic health‑record and practice‑management SaaS, confirmed that an unauthorized actor accessed one of its Amazon Web Services environments from 10 to 16 March 2026. The intrusion disrupted an EHR environment for eight hours and, according to the company’s forensic analysis, resulted in the exfiltration of personal, medical, and financial data belonging to more than 3.75 million people.

Why It Matters for Compliance & Audit Readiness

  • The incident is a textbook example of a data‑exposure breach that SOC 2’s Confidentiality and Privacy principles are designed to prevent and document.
  • Continuous evidence of cloud‑configuration controls, encryption at rest, and privileged‑access monitoring is essential to demonstrate due diligence during an audit.
  • Verisq’s CookiePLUS capability can help map privacy‑law requirements (HIPAA, GDPR, CCPA) to SOC 2 controls and provide ready‑to‑use audit evidence.

Who Is Affected — Health‑care providers, clinics, and any organization that relies on CareCloud’s EHR platform; broadly, the HEALTH_LIFE industry and EHR‑service vendors.

Recommended Actions

  • Verify that your own cloud‑environment configurations (IAM policies, network segmentation, logging) are continuously monitored and aligned with SOC 2 CC6.
  • Review and update data‑retention, encryption, and access‑control policies; capture evidence in a centralized Trust Center.
  • Conduct a privacy‑impact assessment and ensure DSAR processes are documented and testable.

Technical Notes — The attacker gained access to an AWS account, likely via compromised credentials or a mis‑configured role, and extracted data from multiple databases. Exfiltrated data includes full names, addresses, DOB, SSNs, driver’s‑license/passport numbers, medical records, health‑insurance details, and, for a subset, full credit‑card information (including CVV). Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/08/medical-records-ssns-and-bank-details-exposed-in-carecloud-data-breach

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →