CareCloud, a publicly traded New Jersey-based healthcare IT company serving over 45,000 providers across all 50 U.S. states, has confirmed that a March 2026 breach of its AWS cloud environment exposed the personal, medical, and financial records of 3,756,469 patients — making it the fifth-largest healthcare data breach of 2026.
Patient notifications began mailing in late July and early August 2026, more than four months after the intrusion was detected — a timeline drawing scrutiny under HIPAA's 60-day notification requirement.
What Happened
Between March 10 and March 16, 2026, an unauthorized third party accessed one of CareCloud's AWS environments. The attacker claimed to have exfiltrated data from databases within that environment. CareCloud detected the intrusion on March 16 via a network disruption that affected platform and database access for approximately eight hours.
CareCloud engaged third-party cybersecurity experts to investigate and stated it "has eliminated the threat and has not identified any further unauthorized access" since March 16. No specific initial access vector — credential compromise, phishing, or vulnerability exploitation — has been publicly confirmed. No ransomware group or data extortion actor has publicly claimed responsibility.
What Data Was Stolen
The compromised data varies by individual but may include:
- Full name and address
- Date of birth
- Social Security number
- Driver's license / government-issued ID number
- Financial account numbers
- Credit and debit card numbers
- Medical records
- Health insurance information
The combination of medical records, SSNs, and financial data creates significant identity theft and insurance fraud risk for affected individuals.
Scale and Scope
| Metric | Value |
|---|---|
| Total individuals affected | 3,756,469 |
| Ranking in 2026 healthcare breaches | 5th largest |
| Texas residents affected | 270,197+ |
| States with AG notifications filed | California, New Hampshire, Massachusetts, Texas, Maine |
CareCloud offers cloud-based EHR, practice management, revenue cycle management, and patient engagement software to medical practices across 70+ specialties. The company is publicly traded on Nasdaq.
HIPAA Notification Timeline
The breach notification timeline is under scrutiny. HIPAA's Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovery. Key dates:
| Date | Event |
|---|---|
| March 10–16, 2026 | Unauthorized access occurs |
| March 16, 2026 | Intrusion detected |
| March 24, 2026 | CareCloud determines incident is "material" (SEC disclosure trigger) |
| June 24, 2026 | Investigation completed; specific data types confirmed |
| July 25 – August 3, 2026 | Patient breach notifications begin mailing |
| August 18, 2026 | Breach posted to HHS Office for Civil Rights (OCR) breach portal |
The gap between discovery (March 16) and patient notification (late July) spans approximately four months — well outside HIPAA's 60-day window. HHS OCR can open investigations and impose civil monetary penalties for notification delays.
What CareCloud Is Offering
CareCloud stated it would "take steps to strengthen the security of its systems and environments." Affected individuals are being offered 12–24 months of complimentary identity theft protection through IDX, redeemable through December 17, 2026 (offered only where required by state law). The company confirmed cyber insurance covers remediation costs.
Regulatory and Legal Exposure
- HHS OCR: The breach portal listing enables OCR to open a HIPAA investigation. OCR cited risk analysis failures in 53% of its 2025 enforcement actions.
- SEC: CareCloud filed a Form 8-K Item 1.05 (material cybersecurity incident) in March 2026 — part of a growing trend of healthcare breaches triggering investor disclosures under SEC cybersecurity disclosure rules.
- State laws: CareCloud's nationwide footprint triggered notification obligations under multiple state laws, many with stricter timelines than HIPAA.
- Class action litigation: The scale of the breach and the notification delay have attracted class action attention.
Context: 2026 Healthcare Breach Landscape
CareCloud's breach is the fifth-largest health data theft of 2026. The healthcare sector remains a prime target due to the high value of medical records (which combine PII, financial data, and PHI in a single record) and the complex, federated IT environments common in medical practices and health IT vendors.
Recommendations for Affected Individuals
- Enroll in the identity theft protection offered by CareCloud through IDX immediately.
- Place a credit freeze with all three major bureaus (Equifax, Experian, TransUnion) — the most effective protection against new account fraud.
- Monitor Explanation of Benefits (EOB) statements from your health insurer for unfamiliar claims — medical identity theft can result in fraudulent claims filed under your name.
- Be alert to phishing attempts — attackers who obtained your data may use it to craft convincing targeted phishing emails.
- Watch for IRS notices — SSN exposure creates tax fraud risk (fraudulent refund claims).
References
- BleepingComputer — Healthtech firm CareCloud data breach impacts 3.7 million patients
- TechCrunch — CareCloud confirms 3.7M patients had their medical records stolen
- The Record — Electronic health record company CareCloud says 3.7 million people affected by breach
- HIPAA Journal — CareCloud Data Breach Affects 3.3 Million Individuals
- HHS OCR Breach Portal