THE TELL

CareCloud lost 3.75 million medical files. Nobody in that number ever signed up with CareCloud

Your doctor's office picked the billing software. You didn't. And when it got broken into in March, the file that leaked had your diagnoses, your Social Security number and your card — CVV and all.

CareCloud is a company that handles billing and records for medical practices in the United States. Patients never see it, never agree to anything with it, and mostly have never heard the name. In March, someone got inside. This month the company confirmed the count: 3.75 million people.

What was in there is the uncomfortable part. Not just names and emails — medical records, Social Security numbers, and bank and payment card details including the three digits on the back. According to Malwarebytes Labs, which reported the confirmation, the number first put out publicly was roughly ten times smaller. The real one arrived more than five months after the intrusion, in the regulatory filing. We don't know why the first count was so far off. Nobody has explained it.

What it means

Start with the practical difference between the things in that file. A card number is disposable. The bank kills it, mails you a new one, and the fraud is somebody else's accounting problem. A Social Security number is not disposable. A medical history is not disposable. There is no reissue counter for either. That file will still be worth money to somebody in 2031.

Then there's the thing almost nobody plans for: medical identity theft. Someone uses your record to get treatment, tests or prescriptions, and their information — their blood type, their allergies, their diagnoses — gets written into your chart. The bill is the small problem. The chart is the big one, and you usually discover it at the worst possible moment.

A stolen card costs you an afternoon. A stolen medical file follows you.
Share this

And notice the shape of this. You chose your doctor. Your doctor chose a billing vendor. That vendor holds your Social Security number and your card details together in one place, and you were never asked. You can switch clinics tomorrow and the copy stays where it is. That's the part worth being angry about — not the break-in itself, which happens weekly somewhere, but the fact that the consent chain ends two companies before the data does.

Who it matters to

Anyone who has been to a US medical practice that outsources its billing — which is most of them, and you have no reliable way to know if yours is one. Especially people in their twenties and thirties who assume they're not worth robbing: a clean credit file with no loans and no history of disputes is exactly what an identity thief wants, because nothing there looks suspicious yet. Fraud opened in your name at 26 is the thing that shows up when you apply for a car loan at 30. And separately: everyone who gets a breach letter in the next few weeks and has to decide whether the free credit monitoring inside it is worth the ten minutes — it is, and a credit freeze, which is free, is worth more.

What's next

Two checkable things. First, whether 3.75 million holds: breach counts filed with US health regulators get revised, and this one has already moved once, by a factor of about ten. If it moves again, it moves up. Second, the notification letters — when they land, they'll say exactly which categories of data applied to you personally, and that letter is the only document that tells you whether your Social Security number was in the set or just your name. Anyone who calls you about this breach before that letter arrives and asks you to confirm your details is not from CareCloud.

One detail to hold on to

The intrusion was in March. The accurate number came out in August, and it came out through a regulator, not through the company. For five months, 3.75 million people were living with a wrong sense of how exposed they were — most of them not living with any sense of it at all, because they don't know the company exists. The breach lasted a night. The silence lasted a season.

Sources: Malwarebytes Labs, «Medical records, SSNs, and bank details exposed in CareCloud data breach», August 2026, citing CareCloud's breach confirmation.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← Prosecutors almost never lose this room.…Next: Meta Is Back in Court, and the Thing on Tr… →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X