CareCloud tells 3.7 million patients their data was taken in March breach
The healthcare IT firm's SEC filing pointed to an eight-hour outage. The full patient count only landed with regulators months later.

Key points
- CareCloud, a U.S. Healthcare technology company, has told regulators that 3,756,469 people were affected by a breach of one of its Amazon Web Services databases.
- The intrusion ran from March 10 to March 16, 2026, and caused an eight-hour outage that CareCloud disclosed to the U.S. Securities and Exchange Commission in March.
- Notification letters began going out on July 25, offering 12 or 24 months of identity protection through IDX, redeemable until December 17, 2026.
- The sample letter filed with authorities confirms that full names were exposed but doesn't spell out what other patient data was taken.
- No ransomware or extortion group has claimed the attack.
CareCloud, a publicly traded company that handles electronic health records and medical billing for U.S. Doctors' offices, has told the government that a breach earlier this year exposed data on more than 3.7 million patients.
The company filed a report with the U.S. Department of Health and Human Services putting the exact figure at 3,756,469 people. That is the count patients and state attorneys general will now work from.
What happened, in plain English?
Hackers got into one of CareCloud's cloud databases and, according to the company, claimed they had copied data out of it. CareCloud spotted a problem when its platform went down for about eight hours in March.
The intruders were inside an Amazon Web Services environment: storage and computing capacity that CareCloud rents from Amazon to run parts of its systems. In notification letters first reported by BleepingComputer, the company says the unauthorised access ran from March 10 to March 16, 2026.
Because CareCloud sits behind doctors and clinics rather than dealing with patients directly, most people receiving a letter will be hearing the company's name for the first time. Our earlier report on 31 July, "CareCloud Data Breach Exposes Medical and Financial Records of 350,000 People", covered the initial scope; the 3.7 million figure is a very different order of magnitude.
What was disclosed, and when?
CareCloud first flagged the incident in a March filing with the U.S. Securities and Exchange Commission (SEC), the federal regulator that oversees public companies. That filing was made under Item 1.05 of Form 8-K, the section the SEC added in its 2023 cybersecurity disclosure rule for material incidents.
The initial filing described an eight-hour network disruption and loss of access to one database. It didn't name a victim count, which is common in early 8-Ks: companies are required to file within four business days of deciding an incident is material, then amend as facts firm up.
Here is how the disclosure developed:
| Date | Step |
|---|---|
| March 2026 | SEC 8-K filing citing an eight-hour outage |
| March 10 to March 16, 2026 | Window of unauthorised access to the AWS environment |
| July 2026 | Report to HHS naming 3,756,469 affected people |
| July 25, 2026 | Notification letters begin going out to patients |
| December 17, 2026 | Deadline to enrol in the IDX identity protection offer |
The HHS filing is required under the HIPAA Breach Notification Rule, which obliges covered entities and their business associates to report breaches without unreasonable delay.
Should affected patients worry?
Yes, enough to stay alert, but there's no sign yet that stolen files are being sold or leaked. The sample notification confirms only that full names were exposed. Other categories aren't listed, which is unusual and may point to an investigation that isn't finished.
CareCloud's offer covers 12 or 24 months of identity protection through IDX. Letter recipients have until December 17, 2026 to sign up.
Anyone who gets a letter should enrol in the IDX cover and treat any unexpected contact mentioning their doctor or medical bills with real suspicion. Criminals routinely use breach data to make phishing attempts, where fake messages are crafted to extract passwords or card details, sound plausible.
No ransomware gang has claimed the attack. That could change. It could also mean the intruders were after data alone.



