Healthcare technology provider CareCloud has confirmed that a cybersecurity incident disclosed earlier this year affected 3,756,469 individuals, significantly clarifying the scale of a breach involving an environment that contained patient information.
CareCloud provides technology and administrative services to healthcare organizations, including electronic health records, medical billing, practice management, and revenue-cycle services. Because the company operates behind the scenes for healthcare providers, some affected patients may not previously have been familiar with CareCloud.
The incident first became public in March through a filing with the US Securities and Exchange Commission. CareCloud reported that the attack caused approximately eight hours of network disruption and temporarily prevented access to one of its databases. The company also acknowledged that the affected environment contained patient information.
CareCloud subsequently launched an investigation to establish what happened and determine the number of people whose information could have been compromised. The resulting figure was reported to the US Department of Health and Human Services (HHS): 3,756,469 affected individuals.
Additional details emerged when CareCloud began distributing breach notification letters on July 25. According to the notification, an unauthorized third party accessed one of CareCloud’s Amazon Web Services environments between March 10 and March 16, 2026. The intruder claimed to have extracted information from databases located within that environment.
CareCloud’s sample notification confirms that names were among the information involved. However, the publicly available letter does not provide a complete description of all categories of compromised information. It would therefore be inaccurate to conclude from the notification alone that particular medical, financial, or identification records were exposed beyond the information specifically disclosed.
The company is providing affected individuals with identity protection services through IDX. Depending on the recipient, the offered monitoring period lasts either 12 or 24 months, with enrollment available until December 17, 2026.
The scale of the incident is particularly significant because CareCloud provides infrastructure and services to healthcare organizations rather than maintaining direct relationships with many of the patients whose information it processes. Consequently, breach notifications may be the first direct communication some affected individuals receive from the company.
Recipients should be cautious about unexpected communications referencing CareCloud, healthcare providers, or information potentially connected to the incident. Stolen personal information can potentially make phishing attempts more convincing when attackers incorporate accurate details about their targets.
There is currently no public attribution for the intrusion. No known ransomware or data-extortion operation has claimed responsibility for compromising CareCloud, and the identity of the unauthorized party remains undisclosed.