Healthcare firm CareCloud’s data breach affects 3.7 million patients

Healthcare firm CareCloud's data breach affects 3.7 million patients

US healthcare IT company CareCloud has revealed that the data breach incident it suffered earlier this year affected more than 3.7 million people.

The health technology organization is publicly traded and provides electronic health records, medical billing, practice management and revenue cycle services.

The company disclosed the incident in March in a filing with the US Securities and Exchange Commission (SEC), noting that the attack caused an 8-hour network outage on its platform and disrupted access to one of its databases.

image

At the time, the firm said the compromised environment contained patient data, indicating a risk of sensitive medical information being stolen.

After the incident, CareCloud launched an investigation to determine its scope and how many people were potentially affected.

In a report to the US Department of Health and Human Services, the company informed that the number of people affected by the breach was 3,756,469.

CareCloud began distributing data breach notices on July 25, sharing more details uncovered during the investigation.

“The investigation determined that between March 10 and March 16, 2026, an unauthorized third party accessed one of CareCloud’s AWS environments and claimed to have extracted data from databases in that environment,” the notice says.

Other than full names, the sample letter shared with authorities did not specify the type of data exposed.

Notice recipients are offered 12/24 months of Identity Protection service coverage through IDX, which can be used until December 17, 2026.

Because CareCloud does not have a direct relationship with patients, affected individuals will likely be hearing about the company for the first time.

It is recommended to take appropriate actions to mitigate the risks arising from the cyber security incident and remain on high alert for phishing attempts using the stolen data.

At the time of writing, no ransomware group or data extortion gang has claimed responsibility for the CareCloud attack.

BleepingComputer has reached out to CareCloud with questions about the incident and the results of the investigation, and we’ll update this post with the information as we receive it.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *