Skip to main content
Emerging ThreatsData Breaches

CareCloud Breach Exposes 3.7 Million Patient Records

Hospital corridor with patients and staff, medical records desk in foreground.

3,756,469 people have been identified in a CareCloud report to federal authorities as affected by a data breach that cut the company's platform for about eight hours and exposed patient data, the company disclosed in filings and breach notices.

CareCloud's March disclosure and the immediate outage

CareCloud — a publicly traded U.S. healthcare IT company that provides electronic health records, medical billing, practice management, and revenue-cycle services — first disclosed the incident in March via a filing with the U.S. Securities and Exchange Commission. In that filing the company said the attack produced an approximately eight-hour network disruption on its platform and “cut access to one of its databases.” The firm also said the compromised environment contained patient data, raising the possibility that sensitive medical information had been exposed.

Timeline and technical vector reported to authorities

In a notification filed with the U.S. Department of Health and Human Services and shared with affected parties, CareCloud says the unauthorized access occurred between March 10 and March 16, 2026. The company reported that “an unauthorized third party accessed one of CareCloud’s AWS environments and claimed to have exfiltrated data from databases within that environment.”

Scope of impact and what was disclosed to individuals

CareCloud’s report to HHS specifies that 3,756,469 individuals were impacted. The company began distributing breach notifications to individuals on July 25 and included a sample letter with those notices. Beyond listing full names, the sample letter does not specify the types of data that were exposed.

Notification recipients were offered identity protection services through IDX, with coverage terms described as 12 or 24 months and an enrollment deadline redeemable until December 17, 2026.

How affected people are being warned and what they are advised to do

Because CareCloud does not have a direct relationship with patients, many recipients will learn of the company for the first time in the breach notice. The notifications advise recipients to take “appropriate action to mitigate the risks arising from the cybersecurity incident” and to “remain on high alert for phishing attempts leveraging the stolen data,” language included in the company’s shared materials.

What this means for security teams, healthcare providers, and patients

  • Security teams: The company’s report centers on access to an AWS environment and the claim of data exfiltration from databases; teams responsible for cloud deployments and managed EHR systems will note that the vector reported involves a cloud-hosted environment and should watch for evidence of similar access patterns and exfiltration indicators.
  • Healthcare providers and vendors: Providers that rely on third-party EHR and revenue-cycle platforms should expect outreach from vendors and partners as investigations proceed, and should review contractual incident-response obligations given the large number of affected individuals reported by CareCloud.
  • Patients and individuals named in the notice: Individuals notified should evaluate the IDX identity protection offer, watch for phishing or other scams tied to leaked personal information, and be aware that the company’s sample letter lists full names but does not enumerate other data types that may have been exposed.

As of this report, no ransomware groups or data-extortion gangs had claimed responsibility for the event. BleepingComputer said it has contacted CareCloud with questions about the incident and the results of the investigation, and intends to update its reporting if the company responds.

The disclosure sequence — an SEC filing in March, the March 10–16 intrusion window, an HHS report listing 3,756,469 impacted individuals, and patient notifications beginning July 25 with IDX coverage redeemable through December 17, 2026 — establishes the concrete milestones that will shape follow-on regulatory, legal, and operational responses. CareCloud’s public and regulatory filings, and the notices sent to affected individuals, are now the record authorities, customers, and those named in the breach will use to evaluate next steps.

Original story at BleepingComputer