25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

CareCloud Notifies More Than 345,000 Patients About Cyberattack Data Theft

CareCloud Inc., a Somerset, New Jersey-based provider of cloud-based and AI-powered EHR, RCM, PM, and clinical documentation solutions, has determined that data was likely exfiltrated from its systems in a recent security incident.

CareCloud said it experienced a network disruption on March 16, 2026, that impacted one of its electronic health record environments. Third-party cybersecurity experts were engaged to assist with the investigation, who determined that the impacted AWS environment was accessed by an unauthorized third party between March 10 and March 16, 2026. The threat actor claimed to have exfiltrated databases from that environment. The threat actor behind the attack has not been disclosed, and no ransomware group appears to have claimed responsibility for the attack as of August 3, 2026.

CareCloud said it has reviewed that data, and on June 24, 2026, confirmed the data types involved. The exposed/stolen data types vary from individual to individual, and the exact data types are detailed in the individual notification letters. CareCloud has confirmed that the compromised data includes names, addresses, dates of birth, Social Security numbers, driver’s license numbers/government ID numbers, financial account numbers, credit/debit card numbers, and medical and health insurance information.

Notification letters have started to be mailed to the affected individuals, and 24 months of complimentary identity theft protection services have been offered. The data breach is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected; however, CareCloud has confirmed to state attorneys general that this was a significant data breach. Based on data breach summaries published by state attorneys general, at least 345,000 individuals have been affected, including 270,197 Texas residents.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

CareCloud believes it has eliminated the threat and has not identified any further unauthorized access to its AWS environment or other systems since March 16, 2026. The company has confirmed that it will continue to take steps to strengthen the security of its systems and environments to reduce the risk of similar incidents in the future.

March 30, 2026: Healthcare Software Company Announces Breach of its Electronic Health Record Environment

The Somerset, New Jersey-based healthcare software company CareCloud has notified the U.S. Securities and Exchange Commission (SEC) about a security incident that caused network disruption on March 16, 2026. CareCloud is a business associate of hospitals and physician practices and works with more than 45,000 providers. The company provides software solutions, including electronic health records systems, and it was its electronic health record environment that was subject to unauthorized access.

According to the SEC filing, a hacker gained access to one of its six electronic health record environments for a period of around 8 hours, partially disrupting functionality and data access. CareCloud was able to fully restore the environment on the evening of March 16, 2026. CareCloud believes that the threat actor no longer has access to its systems. Initially, the incident was reported to law enforcement, its cyber insurer was notified, and third-party cybersecurity specialists were engaged to assist with the investigation and help with securing its environment. When it became clear that this was a material incident due to the sensitivity of the data stored within the compromised environment and the potential cost of a data breach, the SEC was notified.

CareCloud believes that the incident was contained in the one CareCloud Health environment, and no other business systems were involved. The investigation to determine the nature and scope of the unauthorized activity is ongoing, including the extent to which patient data was accessed or exfiltrated, and the categories of and volume of data involved.

As of the date of the SEC filing, the incident has had no material impact on the company’s operations, and the initial assessment suggests that the incident is not reasonably likely to have a material impact on the company’s financial position or results of operations, although the impact of the incident has yet to be fully assessed. There will naturally be costs associated with remediation and response, legal, regulatory, and notification-related matters, and possible effects on patients, customers, counterparties, reputation, and operations. The company holds cyber insurance policies and believes that it has sufficient insurance coverage to cover any costs.

CareCloud has not publicly disclosed how any of its clients have been affected, nor has it provided an estimate for the number of individuals whose medical records were exposed in the incident. Notifications will be issued to the affected clients and individuals when they have been identified. At the time of publication, no cyber threat actor is known to have claimed responsibility for the attack.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist