CybersecurityHealthNewswireTechnologyWhat's Buzzing

CareCloud data breach exposes info of 3.7M patients

Originally published on: August 21, 2026
▼ Summary

– CareCloud disclosed that a data breach earlier this year affected over 3.7 million individuals, with the exact count reported as 3,756,469 to the U.S. Department of Health and Human Services.
– The incident, first reported in a March SEC filing, caused an 8-hour network disruption and unauthorized access to an AWS environment between March 10 and 16, 2026.
– The compromised environment contained patient data, and the investigation confirmed an unauthorized third party accessed and claimed to have exfiltrated data from databases.
– CareCloud began sending data breach notifications on July 25, offering affected individuals 12 or 24 months of identity protection services through IDX, redeemable until December 17, 2026.
– No ransomware group has claimed responsibility for the attack, and impacted individuals are advised to watch for phishing attempts, as CareCloud lacks a direct patient relationship.

U.S. healthcare technology firm CareCloud has confirmed that a data breach discovered earlier this year now affects more than 3.7 million people. The publicly traded company, which specializes in electronic health records, medical billing, practice management, and revenue-cycle services, first disclosed the incident in a March filing with the U.S. Securities and Exchange Commission (SEC). That filing noted an 8-hour network outage on its platform and restricted access to one of its databases.

At the time, the company acknowledged that the compromised environment contained patient data, raising concerns that sensitive medical information may have been stolen. Since then, CareCloud has conducted an investigation to determine the full scope of the incident and the number of individuals impacted.

In a report submitted to the U. S. Department of Health and Human Services, CareCloud now states that the breach affected 3,756,469 individuals. The company began mailing data breach notifications on July 25, sharing additional findings from its investigation.

The notification explains that between March 10 and March 16, 2026, an unauthorized party accessed one of CareCloud’s AWS environments and claimed to have exfiltrated data from databases within that environment. While the sample letter provided to authorities confirms that full names were exposed, it does not specify what other types of data may have been involved.

Those receiving notification are being offered 12 to 24 months of identity protection services through IDX, with coverage redeemable until December 17, 2026.

Since CareCloud does not maintain direct relationships with patients, many affected individuals may be learning about the company for the first time through this notice. The company advises recipients to take steps to mitigate potential risks from the cybersecurity incident and to stay vigilant against phishing attempts that could exploit the stolen data.

As of now, no ransomware group or data extortion gang has claimed responsibility for the attack. BleepingComputer has reached out to CareCloud for additional details about the incident and the investigation’s findings, and this story will be updated if more information becomes available.

(Source: BleepingComputer)

Topics

healthcare data breach 98% cybersecurity incident 95% patient data exposure 93% breach investigation 90% sec filing 87% notification process 85% cloud security 84% identity protection services 82% regulatory reporting 81% phishing risk 79%