CareCloud tells 3.7 million patients their data was taken in March breach

The healthcare IT firm's SEC filing pointed to an eight-hour outage. The full patient count only landed with regulators months later.

ThreatVectr Newsdesk· 4 min read
Photoreal editorial shot of a modern glass office tower at dusk with cold blue interior lighting on empty open-plan floors, a faint reflection of code-like patt
Share

Key points

  • CareCloud, a U.S. healthcare technology company, has told regulators that 3,756,469 people were affected by a breach of one of its Amazon Web Services databases.
  • The intrusion ran from March 10 to March 16, 2026, and caused an eight-hour outage that CareCloud disclosed to the U.S. Securities and Exchange Commission in March.
  • Notification letters began going out on July 25, offering 12 or 24 months of identity protection through IDX, redeemable until December 17, 2026.
  • The sample letter filed with authorities names full names as exposed but does not spell out what other patient data was taken.
  • No ransomware or extortion group has claimed the attack.

CareCloud, a publicly traded company that handles electronic health records and medical billing for U.S. doctors' offices, has told the government that a breach earlier this year exposed data on more than 3.7 million patients.

The company filed a report with the U.S. Department of Health and Human Services putting the exact figure at 3,756,469 people. That is the count patients and state attorneys general will now work from.

What happened, in plain English?

Hackers got into one of CareCloud's cloud databases and, according to the company, said they had copied data out of it. CareCloud spotted a problem when its platform went down for about eight hours in March.

The intruders were inside an Amazon Web Services environment, meaning storage and computing space CareCloud rents from Amazon to run parts of its systems. In its notification letters, first reported by BleepingComputer, the company says the unauthorised access ran from March 10 to March 16, 2026.

Because CareCloud sits behind doctors and clinics rather than dealing with patients directly, most people receiving a letter will be hearing the company's name for the first time.

What was disclosed, and when?

CareCloud first flagged the incident in a March filing with the U.S. Securities and Exchange Commission (SEC), the federal regulator that oversees public companies. That filing was made under Item 1.05 of Form 8-K, the section the SEC added in its 2023 final cybersecurity disclosure rule for material incidents.

The initial filing described an eight-hour network disruption and loss of access to one database. It stopped short of naming a victim count, which is common in early 8-Ks: companies are required to file within four business days of deciding an incident is material, then amend as facts firm up.

Here is how the disclosure has developed:

Date Step
March 2026 SEC 8-K filing citing an eight-hour outage
March 10 to March 16, 2026 Window of unauthorised access to the AWS environment
July 2026 Report to HHS naming 3,756,469 affected people
July 25, 2026 Notification letters begin going out to patients
December 17, 2026 Deadline to enrol in the IDX identity protection offer

The HHS filing is required under the HIPAA Breach Notification Rule at 45 CFR 164.408, which obliges covered entities and their business associates to report breaches touching 500 or more people without unreasonable delay and in no case later than 60 days after discovery.

Should affected patients worry?

Yes, enough to stay alert, but there is no sign yet that stolen files are being sold or leaked. The sample notification filed with regulators only confirms that full names were exposed. It does not list other data types, which is unusual and may reflect a still-open investigation.

CareCloud is offering 12 or 24 months of identity protection through IDX, and letter recipients have until December 17, 2026 to sign up.

Practical steps for anyone who receives a letter: enrol in the IDX cover, treat any unexpected email or text mentioning your doctor, insurer or medical bills with suspicion, and be slow to click links in those messages. Criminals often use real breach data to make phishing, where scammers send fake messages to trick people into handing over passwords or card details, sound more convincing.

No ransomware gang has claimed the attack. That could change. It could also mean the intruders were after data alone.

© 2026 Threat Vectr