
Brookhaven ENT, Allergy, Aesthetics & Hearing disclosed a major data security incident following a breach at its third-party provider, CareCloud, that reportedly compromised the personal information of more than 3.7 million individuals.
Brookhaven ENT is a medical clinic specialising in the diagnosis and treatment of ENT disorders, chronic sinus conditions, allergies, hearing loss, and skin conditions, along with facial aesthetic and laser treatments. The practice uses CareCloud as its third-party electronic health record service provider, which supports the management and storage of patient health information and clinical records.
In a data security incident notice posted on its website, Brookhaven ENT said that on March 16, CareCloud detected a network disruption affecting one of its electronic health record environments. The healthcare data management company immediately launched an investigation, with support from external cybersecurity experts, to assess the nature and scope of the incident.
It also took steps to secure the affected systems and notified relevant law enforcement authorities about the same.
“The investigation determined that an unauthorised third party accessed one of CareCloud’s AWS-hosted environments between March 10, 2026, and March 16, 2026, and claimed to have acquired data from databases within that environment. CareCloud reports that there has been no evidence of unauthorised activity within the affected environment since March 16, 2026,” Brookhaven ENT said.
The compromised information reportedly included names, dates of birth, email addresses, treatment details, medical record numbers, appointment information, and other sensitive data. Brookhaven ENT reported the incident to the U.S. Department of Health and Human Services and said that at least 30,403 individuals were affected.
“CareCloud undertook a comprehensive investigation with the assistance of external cybersecurity professionals. CareCloud reports that it secured the affected environment, contained the threat, eliminated unauthorised access, and implemented additional measures to strengthen the security of its systems and data,” reads the notice.
Although CareCloud and Brookhaven ENT found no indication that the exposed information had been misused, it urged affected individuals to remain vigilant by regularly reviewing their credit reports, account and benefits statements, and to report any suspicious activity to law enforcement agencies, including local police and the state attorney general.
The healthcare data management company has also offered complimentary credit monitoring services through IDX to all affected individuals.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543