CareCloud Data Breach Exposes Medical and Financial Records of 350,000 People

A healthcare IT company says hackers spent nearly a week inside its cloud storage system, making off with Social Security numbers, credit card details, and medical records.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Hackers accessed a CareCloud cloud storage environment between March 10 and March 16, 2026, disrupting one of its healthcare record systems on the final day.
  • At least 350,000 people have had personal, financial, and medical information stolen, based on filings with multiple state attorneys general.
  • Stolen data includes Social Security numbers, driver's licence numbers, credit and debit card numbers, and health insurance details.
  • CareCloud confirmed the scope of the breach on June 24, 2026, roughly three and a half months after the intrusion.
  • Affected individuals are being offered 24 months of free credit monitoring and identity theft protection, including a $1,000,000 insurance reimbursement policy.

CareCloud, a Florida-based company that sells software and data services to medical practices and hospitals, is sending breach notification letters to more than 350,000 people after criminals broke into one of its cloud storage systems and copied sensitive records.

The intrusion took place inside an AWS environment, meaning cloud storage rented from Amazon Web Services. Think of it as a filing cabinet in the sky: CareCloud stores patient and billing data there so its healthcare clients can access records easily. Between March 10 and March 16, 2026, unauthorised visitors had the run of that cabinet.

What information was taken?

Nearly everything you would not want a stranger to have. CareCloud says the stolen records may include names, home addresses, dates of birth, Social Security numbers, government ID numbers, driver's licence numbers, financial account numbers, and credit and debit card details, alongside medical records and health insurance information.

Put plainly: enough to open credit cards, file false tax returns, or impersonate someone to their insurer.

Why did it take so long to know?

The company says its investigation only confirmed on June 24, 2026, that personal and financial data had actually left its systems. That is about 15 weeks after the attackers first got in. Healthcare breach investigations are often slow because the storage environments are large and the logs needed to trace exactly which files were copied take time to parse.

CareCloud says it brought in outside cybersecurity specialists, shut the attackers out, and has confirmed no one is still lurking in its systems. SecurityWeek first reported the story, noting the company has not yet named the group responsible for the attack.

Detail Fact
Intrusion window March 10 to March 16, 2026
System disrupted March 16, 2026
Breach confirmed June 24, 2026
People affected At least 350,000
Free monitoring offered 24 months
Insurance coverage included $1,000,000 per person

What should affected people do?

Accept the free credit monitoring CareCloud is offering. Watch for unexpected bills from medical providers you have never visited, a classic sign that someone is using stolen health insurance details. If you receive a notification letter, place a free credit freeze with each of the three major credit bureaus, which stops anyone opening new accounts in your name even if they have your Social Security number. Keep an eye on explanation-of-benefits letters from your insurer for treatments you did not receive.

Common questions

How will I know if my records were taken?

CareCloud is mailing letters to everyone whose information it believes was exposed. If you are or were a patient at a practice that uses CareCloud software and have not heard anything by late July 2026, contact your healthcare provider directly.

Is the breach still ongoing?

No. CareCloud says external investigators confirmed the attackers no longer have access, and the affected environment has been secured.

© 2026 Threat Vectr