When CareCloud first disclosed its March security incident, attackers had accessed one of its electronic health record environments and disrupted systems for several hours. At the time, CareCloud had not confirmed whether patient information had been stolen or how many people were affected.
Five months later, the scope is clearer.
CareCloud has confirmed that attackers exfiltrated data from its Amazon Web Services environment, affecting 3,756,469 people.
The breach exposed medical records along with information that can be used for identity theft and financial fraud, making it one of the largest reported healthcare breaches of 2026.
Why It Matters: CareCloud’s initial disclosure captured only part of the eventual impact. Systems were restored within hours, yet determining what happened to the data took months. The case shows why recovery time is a poor proxy for breach severity, particularly for healthcare technology providers that hold patient information for thousands of organizations.
- The March Intrusion Is Now Confirmed as a Major Data Theft: CareCloud initially knew attackers had entered an electronic health record environment, while the status of patient data remained unclear. Its investigation later found that information was exfiltrated from databases in the compromised AWS environment. The finding answers one of the largest questions left open after the original incident.
- The Affected Population Is Far Larger Than Early Disclosures Indicated: State filings in July accounted for roughly 350,000 people. The HHS breach tracker later raised the total to 3,756,469. The increase shows how significantly the known scope of a breach can change as an investigation determines which records and individuals were affected.
- The Stolen Information Creates Lasting Risk: Compromised records include Social Security numbers, government identification, health insurance information, medical information and financial data. Full payment-card details were also taken for a limited subset of people. Medical and identity records have a long useful life for criminals because much of the underlying information cannot simply be reset after exposure.
- Attackers Were Inside the Environment for Days: The original incident focused on the March 16 disruption, which affected systems for several hours before service was restored. Investigators have since determined that attackers accessed the AWS environment between March 10 and March 16. That timeline shows the difference between when an intrusion becomes operationally visible and when the compromise actually begins.
- Several Questions Remain Unanswered: No known cybercrime group has publicly claimed the attack, and CareCloud has not identified who was responsible. It is also unclear whether a ransom was demanded or paid. Those unknowns remain months after the company confirmed the initial intrusion, even though the consequences for affected patients are now much clearer.
CareCloud Data Breach Impact Grows to 3.7 Million Individuals – Security Week

