3.7 million people just found out their medical records got stolen. Not "might have." Did.
There is not a clearer sign that you need to take the steps necessary to protect your own data than this.
It is wild how, year after year, breach after breach, the problem doesn't get fixed. Or prioritized. Or anything. Third-party risk management still isn't treated like the critical-path security practice it is. In the year of Our Lord 2026, we're still watching breaches of this size happen that were entirely preventable (if the companies involved had the will to prevent them, that is).
I'm not saying software can be made breach-proof. It can't. Not possible. But you can absolutely close the known vulnerabilities in your architecture, and then actually go fix them. A cybersecurity pundit I respect pointed out that stuffing that many records into one bucket is a design choice (a bad one). Those buckets could have been structured to limit the damage. Harm reduction. It's a thing companies could choose to do. Or, apparently, not. Repeatedly. Hurrah for yet another year where shareholder value beats basic protection of customer data.
So it's on us to start teaching people (the actual victims of these breaches) how to protect themselves, since the industry is clearly too busy navel-gazing to do it for them. It's time to make compromise survivable. It's time to give people's data the level of concern it deserves.
What do the 3.7 million people in this breach do next? Do they know how to freeze their credit and lock down their accounts? Switch to real passphrases with MFA? Know whether they're on the hook for IoMT (Internet of Medical Things) exposure, or how to double-check and back up their own medical records before something changes? Because this breach makes it painfully clear: industry can't even manage bare-minimum harm reduction for you and yours. You're on your own here.
So what do you do with that?
Kind of excellent of CareCloud to make our point for us, honestly. Because 3.7 million people are, right now, scrambling to put in place exactly the safeguards we teach you to build before anything goes wrong.

That's the whole idea behind Digital Caregiving: get ahead of the breach that hasn't happened yet, instead of cleaning up after the one that has. Come build your safety net with us before you need it, not after.
Signups end tonight. Class starts tomorrow.
Join us for tea!
CybersecuriTea is a free, plain-English guide to digital safety, designed for families, friends, and the folks you love. Subscribe today and get weekly tips to help keep your digital life secure.
Or, if you’d like to support our work and keep the kettle warm for everyone:
This content may contain affiliate links. If you choose to sign up or make a purchase through them, we may earn a small commission, at no additional cost to you. Thank you for supporting CybersecuriTea.





