CareCloud Inc. , a Somerset, New Jersey-based provider of cloud-based and AI-powered EHR, RCM, PM, and clinical documentation solutions, has determined that data was likely exfiltrated from its systems in a recent security incident. CareCloud said it experienced a network disruption on March 16, 2026, that impacted one of its electronic health record environments.
Third-party cybersecurity experts were engaged to assist with the investigation, who determined that the impacted AWS environment was accessed by an unauthorized third party between March 10 and March 16, 2026. The threat actor claimed to have exfiltrated databases from that environment. The threat actor behind the attack has not been disclosed, and no ransomware group appears to have claimed responsibility for the attack as of August 3, 2026.
CareCloud said it has reviewed that data, and on June 24, 2026, confirmed the data types involved. The exposed/stolen data types vary from individual to individual, and the exact data types are detailed in the individual notification letters. CareCloud has confirmed that the compromised data includes names, addresses, dates of birth, Social Security numbers, driver’s license numbers/government ID numbers, financial account numbers, credit/debit card numbers, and medical and health insurance information.
Notification letters have started to be mailed to the affected individuals, and 24 months of complimentary identity theft protection services have been offered. The data breach is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected; however, CareCloud has confirmed to state attorneys general that this was a significant data breach.
Based on data breach summaries published by state attorneys general, at least 345,000 individuals have been affected, including 270,197 Texas residents. CareCloud believes it has eliminated the threat and has not identified any further unauthorized access to its AWS environment or other systems since March 16, 2026. The company has confirmed that it will continue to take steps to strengthen the security of its systems and environments to reduce the risk of similar incidents in the future.
March 30, 2026: Healthcare Software Company Announces Breach of its Electronic Health Record Environment The Somerset, New Jersey-based healthcare software company CareCloud has notified the U. S. Securities and Exchange Commission (SEC) about a security incident that caused network disruption on March 16, 2026.
CareCloud is a business associate of hospitals and physician practices and works with more than 45,000 providers. The company provides software solutions, including electronic health records systems, and it was its electronic health record environment that was subject to unauthorized access. According to the SEC filing, a hacker gained access to one of its six electronic health record environments for a period of around 8 hours, partially disrupting functionality and data access.
CareCloud was able to fully restore the environment on the evening of March 16, 2026. CareCloud believes that the threat actor no longer has access to its systems. Initially, the incident was reported to law enforcement, its cyber insurer was notified, and third-party cybersecurity specialists were engaged to assist with the investigation and help with securing its environment.
When it became clear that this was a material incident due to the sensitivity of the data stored within the compromised environment and the potential cost of a data breach, the SEC was notified. CareCloud believes that the incident was contained in the one CareCloud Health environment, and no other business systems were involved. The investigation to determine the nature and scope of the unauthorized activity is ongoing, including the extent to which patient data was accessed or exfiltrated, and the categories of and volume of data involved.
As of the date of the SEC filing, the incident has had no material impact on the company’s operations, and the initial assessment suggests that the incident is not reasonably likely to have a material impact on the company’s financial position or results of operations, although the impact of the incident has yet to be fully assessed. There will naturally be costs associated with remediation and response, legal, regulatory, and notification-related matters, and possible effects on patients, customers, counterparties, reputation, and operations.
The company holds cyber insurance policies and believes that it has sufficient insurance coverage to cover any costs. CareCloud has not publicly disclosed how any of its clients have been affected, nor has it provided an estimate for the number of individuals whose medical records were exposed in the incident. Notifications will be issued to the affected clients and individuals when they have been identified.
At the time of publication, no cyber threat actor is known to have claimed responsibility for the attack. The post CareCloud Notifies More Than 345,000 Patients About Cyberattack Data Theft appeared first on The HIPAA Journal .
Originally published at hipaajournal.com
