New Jersey-based healthcare technology firm CareCloud has confirmed that a data breach affecting its cloud electronic health record (EHR) platform exposed the sensitive personal and medical information of approximately 3.75 million patients. The breach, which occurred over a six-day window in March 2026, has since grown more than tenfold from its initial disclosure estimate — placing it among the five largest health data thefts of 2026 to date.
What Happened
CareCloud detected a network disruption on March 16, 2026 and engaged third-party forensic investigators. Their analysis determined that an unauthorized party gained access to one of CareCloud's AWS-hosted EHR environments between March 10 and March 16 — a six-day exposure window during which the threat actor claimed to have exfiltrated database contents.
The breach does not appear to involve ransomware deployment. No ransomware group has publicly claimed responsibility; the incident is assessed as a targeted data exfiltration operation.
What Data Was Exposed
According to CareCloud's breach disclosures, the following categories of information were compromised for affected individuals:
- Full names and postal addresses
- Social Security numbers
- Driver's license numbers
- Health insurance information
The combination of SSNs, driver's license numbers, and detailed insurance data creates significant exposure for affected individuals — enabling identity fraud, insurance fraud, and medical identity theft.
Scale of the Breach
CareCloud initially reported the incident to the HHS Office for Civil Rights (as required under HIPAA for breaches affecting 500 or more individuals) at a figure of approximately 350,000 affected individuals. By August 18, 2026, the HHS breach portal reflected an updated count of 3,371,508, followed by a further revision to 3,756,469 the following day. The investigation remains ongoing, and the final affected count may rise further.
CareCloud's platform serves more than 45,000 medical practitioners nationwide across its cloud EHR and healthcare data management services, explaining the wide distribution of potentially affected patients across multiple provider organizations.
Who Is CareCloud?
Founded in 2009 and headquartered in Somerset, New Jersey, CareCloud provides cloud-based practice management, EHR, and revenue cycle management services to outpatient medical practices across the United States. The company reported Q2 2026 revenue of $31.9 million — a 16% year-over-year increase — but net income fell to $1.1 million from $2.9 million in the same period a year earlier, partly reflecting escalating breach-related remediation costs.
Regulatory and Legal Implications
CareCloud filed mandatory breach notifications with both the Department of Health and Human Services under HIPAA and notified the Securities and Exchange Commission given the potential financial materiality of the incident.
Breaches involving SSNs and medical records at this scale typically trigger:
- State attorney general notifications across all states where affected individuals reside
- Class action litigation from affected patients
- OCR investigation into potential HIPAA safeguard failures relating to the AWS environment
- Mandatory credit monitoring offerings for affected individuals
What Affected Individuals Should Do
Patients who receive notification letters from CareCloud — or who believe they may have received care from a CareCloud-served practice — should take the following steps:
- Monitor credit reports through all three major bureaus (Equifax, Experian, TransUnion). Free weekly reports are available at AnnualCreditReport.com.
- Place a credit freeze at each bureau — the most effective protection against new account fraud using stolen SSNs.
- File an IRS Identity Protection PIN to prevent fraudulent tax returns filed with your SSN.
- Watch for medical billing fraud — review Explanation of Benefits statements from your insurer for services you did not receive.
- Be alert to phishing — threat actors may leverage the stolen contact information to send targeted phishing emails or calls impersonating CareCloud, HHS, or your healthcare provider.
Context: Healthcare Remains a Prime Target
The healthcare sector continues to be disproportionately targeted by data theft operations due to the high resale value of complete medical records (which command significantly more on criminal markets than financial records alone) and the historically weaker perimeter defenses of many healthcare organizations relative to their data sensitivity.
The CareCloud incident follows a pattern of cloud-hosted healthcare platforms being targeted through their AWS and Azure environments — underscoring the importance of tightly scoped IAM permissions, network segmentation, and continuous cloud security posture monitoring (CSPM) in environments that hold protected health information (PHI).