The CareCloud data breach has affected more than 3.7 million people, according to a filing with the US Department of Health and Human Services.
CareCloud provides electronic health records, medical billing, practice-management and revenue-cycle services to healthcare organisations. The company first disclosed the security incident in March after an attacker accessed part of its CareCloud Health environment.
Its subsequent investigation found that an unauthorised third party accessed one of its Amazon Web Services environments between March 10 and March 16, 2026.
CareCloud data breach disrupted EHR access
The company detected the incident on March 16. It caused an eight-hour network disruption and partly affected functionality and data access in one of CareCloud’s six electronic health record environments.
CareCloud restored functionality and access later that day. It said the incident remained limited to the CareCloud Health environment and did not affect its other platforms, divisions, systems or data environments.
The company also brought in external cybersecurity specialists to secure the affected environment and investigate the intrusion.
According to its latest disclosures, the unauthorised party accessed a cloud account supporting the electronic health record environment and exfiltrated patient-related information. CareCloud said it found no evidence of additional unauthorised activity after March 16.
More than 3.75 million people are affected
CareCloud reported that 3,756,469 individuals were affected by the incident.
Notification letters began going out on July 25. The company does not directly serve patients, so many people who receive notifications may not recognise the CareCloud name.
A sample notification shared with authorities confirms that the attacker claimed to have taken data from databases in the affected AWS environment. However, the sample letter does not specify the exact data types for each recipient beyond full names.
The categories of information may vary by individual. Earlier company disclosures said the affected environment stored patient information, while later filings confirmed that the stolen data included personally identifiable information and protected health information.
Affected individuals should watch for scams
CareCloud is offering identity-protection services through IDX for either 12 or 24 months, depending on the recipient. Eligible people must enrol by December 17, 2026.
People affected by the CareCloud data breach should remain alert for phishing emails, calls and messages that use personal or healthcare-related details to appear credible.
They should also review any breach notification carefully, activate available protection services and watch for unfamiliar activity involving financial accounts or identity records.
No ransomware group or extortion gang had publicly claimed responsibility for the incident at the time of publication. CareCloud has not publicly identified the attacker.


0 responses to “CareCloud Data Breach Affects 3.7 Million Patients”