CareCloud Data Breach Exposes Health, Financial Data of 350,000 Patients
CareCloud, Inc., a New Jersey-based healthcare technology provider, has confirmed a data security incident affecting between 345,000 and 350,000 individuals after unauthorized actors accessed one of its AWS-hosted electronic health record (EHR) environments.
The breach, disclosed in an updated notice dated July 1, 2026, exposed a mix of health, insurance, and, in limited cases, financial data belonging to patients across CareCloud’s healthcare provider network.
CareCloud detected a network disruption within its CareCloud Health division on March 16, 2026, affecting one of the six EHR environments the company operates.
CareCloud Data Breach
Forensic investigators later determined that an unauthorized third party had accessed one of CareCloud’s AWS environments between March 10 and March 16, 2026, and claimed to have exfiltrated data from databases within that environment.
Regulatory filings submitted to the California Attorney General’s office confirmed the attackers maintained access to the EHR data store for at least six consecutive days before CareCloud’s response team, working with an external cyber advisory firm, contained the intrusion.
Initial disclosures in late March described only an eight-hour service disruption, with functionality restored the same day and no confirmed data exfiltration at that time.
It wasn’t until June 24, 2026, that a deeper forensic review confirmed sensitive data had indeed been affected, triggering formal notification obligations under state and federal breach disclosure laws.
Exposed Data
According to CareCloud’s notice, affected data varied by individual but generally included full names combined with one or more of the following:
- Home addresses and dates of birth
- Social Security numbers and driver’s license numbers
- Health insurance member numbers, insurer names, policy and group numbers
- Primary care and referring physician details
- Medications, allergies, and other demographic and health insurance information
For a limited subset of individuals, complete credit card information, including CVV numbers, was also compromised, elevating the risk profile for that smaller group beyond typical medical identity theft.
No ransomware or extortion group has publicly claimed responsibility for the attack as of this writing, and the threat actor’s identity remains undisclosed.
CareCloud engaged external cybersecurity experts to secure the affected AWS environment, eliminate the threat, and confirm no persistent unauthorized access remained afterward.
The company also reported the incident to law enforcement and stated there has been no evidence of unauthorized activity within its environment since March 16, 2026.
CareCloud, which serves over 45,000 healthcare providers through its EHR platforms, maintains that the intrusion was contained to a single environment and did not affect its other systems or client platforms.
CareCloud has established a dedicated, confidential response line at 800-411-9670, staffed Monday through Friday from 9 a.m. to 5 p.m. ET, for individuals seeking to confirm whether their information was involved.
The company is advising affected individuals to place a one-year fraud alert with any of the three major credit bureaus, since notifying one automatically alerts the other two, and to consider a free credit freeze through Equifax, Experian, or TransUnion.
CareCloud states it is not currently aware of any confirmed identity fraud stemming directly from the incident but recommends these precautions out of caution.
The breach underscores growing scrutiny of cloud-hosted healthcare infrastructure, as attackers increasingly target third-party SaaS environments that aggregate protected health information from many provider organizations simultaneously.
No Comment! Be the first one.