The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact. The post CareCloud Data Breach Impact Grows to 3.7 Million Individuals appeared first on SecurityWeek.

A recent report indicates that a data breach affecting CareCloud, a health information technology provider, has expanded significantly in scope. Initially estimated to impact approximately 350,000 individuals, the incident is now reported to affect 3.7 million individuals, according to updated information on the U.S. Department of Health and Human Services (HHS) breach tracker.
The specific technical mechanisms of the breach have not been detailed in the available information. However, data breaches in healthcare organizations often stem from a variety of vectors, including sophisticated cyberattacks such as ransomware or phishing campaigns, or more straightforward vulnerabilities like misconfigured servers, unpatched software, or insider threats. Given the nature of healthcare data, such incidents typically involve unauthorized access to sensitive personal health information (PHI) and personally identifiable information (PII).
CareCloud provides a range of cloud-based solutions for healthcare practices, including electronic health records (EHR), practice management, and revenue cycle management. As such, the data potentially compromised in such a breach could include patient names, addresses, dates of birth, medical record numbers, health insurance information, and clinical data. The widespread impact suggests a compromise within a core system or a widely used service component that processes data for a large number of patients across multiple client practices.
The significant increase in the reported number of affected individuals from 350,000 to 3.7 million suggests that the initial assessment of the breach's scope was either incomplete or that further investigation uncovered a broader compromise. This often occurs as forensic investigations mature, revealing additional affected systems or data repositories that were not immediately apparent.
Mitigation for this class of issue typically involves a multi-layered security approach. This includes robust access controls, regular security audits, timely patching of all systems, employee training on cybersecurity best practices, and strong incident response plans. For healthcare providers, compliance with HIPAA regulations mandates stringent security measures to protect patient data, and breaches often trigger notification requirements to affected individuals and regulatory bodies.
The expanded impact of this breach underscores the persistent and evolving threat landscape facing the healthcare sector. Healthcare organizations remain prime targets for cybercriminals due to the valuable and sensitive nature of the data they hold. Incidents like this highlight the critical importance of continuous vigilance, proactive security investments, and thorough post-incident analysis to accurately assess and respond to data compromises.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]