CareCloud Data Breach Exposes Medical and Financial Records of 350,000 People
A healthcare IT company says hackers spent nearly a week inside its cloud storage system, making off with Social Security numbers, credit card details, and medical records.

Key points
- Hackers accessed a CareCloud cloud storage environment between March 10 and March 16, 2026, disrupting an electronic health record system on the final day.
- At least 350,000 people have had personal and medical information stolen, based on filings with multiple state attorneys general.
- Stolen data includes Social Security numbers, driver's licence numbers, credit and debit card numbers, and health insurance details.
- CareCloud confirmed the scope of the breach on June 24, 2026, roughly fifteen weeks after the intrusion began.
- Affected individuals are being offered 24 months of free credit monitoring and identity theft protection, including a $1,000,000 insurance reimbursement policy.
CareCloud, a Florida-based company selling software and data services to medical practices and hospitals, is notifying more than 350,000 people after criminals broke into one of its cloud storage systems and copied sensitive records.
The intrusion took place inside an AWS environment, meaning cloud storage rented from Amazon Web Services. Think of it as a filing cabinet in the sky: CareCloud stores patient and billing data there so its healthcare clients can access records easily. Between March 10 and March 16, 2026, unauthorised visitors had the run of that cabinet.
What information was taken?
Nearly everything you wouldn't want a stranger to have. The stolen records may include names, home addresses, dates of birth, Social Security numbers, government ID numbers, driver's licence numbers, financial account numbers, credit and debit card details, plus medical records and health insurance information.
That's enough to open new credit accounts, file false tax returns, or impersonate someone to their insurer.
Why did it take so long to know?
The company's investigation only confirmed on June 24, 2026, that data had actually left its systems. About fifteen weeks after the attackers first got in. Healthcare breach investigations run slow because storage environments are large and the logs needed to trace exactly which files were copied take time to parse. The DentaQuest breach we reported on 27 July followed a similar pattern: intrusion confirmed weeks after the fact, scope unclear for longer still.
CareCloud says it brought in outside cybersecurity specialists, shut the attackers out, and confirmed no one is still lurking. SecurityWeek first reported the story, noting the company hasn't named the group responsible.
| Detail | Fact |
|---|---|
| Intrusion window | March 10 to March 16, 2026 |
| System disrupted | March 16, 2026 |
| Breach confirmed | June 24, 2026 |
| People affected | At least 350,000 |
| Free monitoring offered | 24 months |
| Insurance coverage included | $1,000,000 per person |
What should affected people do?
Accept the free credit monitoring CareCloud is offering. Watch for unexpected bills from medical providers you've never visited, a classic sign that someone is using stolen health insurance details. If you receive a notification letter, place a free credit freeze with each of the three major credit bureaus: that stops anyone opening new accounts in your name even if they have your Social Security number. Our 23 July guide on what to do after a data breach walks through each step.
The blunt judgement here: fifteen weeks to confirm exfiltration from a cloud environment isn't unusual, but it is a problem. By the time letters land, criminals have had months to act on the data.
Common questions
How will I know if my records were taken?
CareCloud is mailing letters to everyone whose information it believes was exposed. If you were a patient at a practice using CareCloud software and haven't heard anything by late July 2026, contact your healthcare provider directly.
Is the breach still ongoing?
No. CareCloud says external investigators confirmed the attackers no longer have access and the affected environment has been secured.



