CSIDB logo
Incident

CareCloud

Incident posture

Attack window
Mar 2026
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-08-31 18:11

Linked entities

Victim
CareCloud
Threat actors
0 actors
Sources
16 sources

Timeline

Occurred
Mar 2026
Discovered
Mar 2026
Disclosed
Mar 2026
Resolved
Mar 2026

Summary

CareCloud reported that unauthorized parties gained access to one of its Amazon Web Services hosted electronic health record environments, leading to the likely exfiltration of databases containing personal, financial, and medical information. The breach affected hundreds of thousands of individuals, exposing names, addresses, dates of birth, Social Security numbers, government identification numbers, financial account details, and health data, prompting the company to offer identity theft protection services and notify regulators and affected individuals.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On March 16 2026 CareCloud detected a temporary network disruption that affected one of its six electronic health record environments for approximately eight hours, after which functionality was restored. The company promptly reported the incident to law enforcement, notified its cyber insurer, and engaged third‑party cybersecurity experts to conduct a forensic analysis. A subsequent SEC filing disclosed that unauthorized access to the affected AWS environment had occurred between March 10 and March 16, and that the threat actor claimed to have exfiltrated data from databases stored there. CareCloud stated that it believed the threat actor no longer had access to its systems after the environment was secured and restored.

By June 24 2026 the investigation had confirmed that personal, financial, and medical information had been compromised, including names, addresses, dates of birth, Social Security numbers, driver’s license or other government ID numbers, financial account numbers, credit or debit card numbers, and medical and health insurance information, with a limited number of individuals also having full credit card details including CVV exposed. CareCloud noted that it had no evidence the stolen data had been misused. Based on filings with state attorneys general, at least 345,000 individuals were affected, including 270,197 Texas residents, and the company began mailing notification letters to those impacted while offering 24 months of complimentary identity theft protection services.

CareCloud engaged external cybersecurity experts to secure the affected environment, eliminate the threat, and verify that no persistent unauthorized access remained. The company reported that the incident was confined to its CareCloud Health division and did not affect other platforms, divisions, systems, data, or environments. Although CareCloud indicated that the breach had not had a material impact on its operations and that any potential losses should be covered by cyberinsurance, it acknowledged that remediation, response, legal, regulatory, and notification‑related expenses could arise and that the incident could affect patients, customers, counterparties, reputation, and ongoing operations. The organization stated that it would continue to strengthen the security of its systems to reduce the risk of similar incidents in the future. No ransomware group had publicly claimed responsibility for the attack as of the latest available information.

Sources

Sources available to members: 16 sources.

CSIDB