3.7 million patients, and not one of them chose CareCloud
You have almost certainly never heard of CareCloud. It stores electronic medical records for tens of thousands of American healthcare providers, which is how a company you never signed up with ends up holding your Social Security number.
The final count reached the Department of Health and Human Services this week: 3,756,469 people. The intrusion itself was short and, to CareCloud, old news - an unauthorised third party sat inside one of its Amazon Web Services environments from 10 to 16 March, and the company filed an SEC disclosure at the time. What took months was establishing what actually left. The answer, per the notification letters: names, postal addresses, Social Security numbers, medical and health information, passport and driving licence numbers, and banking and financial details. That is close to the complete set, and it makes this the fifth-largest US healthcare breach of 2026 so far.
Letters began going out on 25 July, offering 12 or 24 months of identity monitoring through IDX, redeemable until 17 December. Take it if one arrives, but treat it as the floor rather than the fix. A credit freeze with all three bureaus is free, takes roughly ten minutes each, and actually stops new accounts being opened in your name - monitoring only tells you afterwards.
Then expect phone calls. Stolen medical records make unusually convincing scripts, because the caller can name your insurer, your provider, a real procedure you had. That specificity is exactly what makes people lower their guard, and nobody legitimate needs your Social Security number to discuss a breach they caused. Tendvane can't undo a break-in at a company you never dealt with; its Privacy and accounts check covers the part that is yours, showing which accounts your PC is signed into and what's exposed on the machine itself.