CareCloud
Incident posture
Linked entities
- Victim
- CareCloud
- Threat actors
- 0 actors
- Sources
- 16 sources
Timeline
Summary
CareCloud reported that unauthorized parties gained access to one of its Amazon Web Services hosted electronic health record environments, leading to the likely exfiltration of databases containing personal, financial, and medical information. The breach affected hundreds of thousands of individuals, exposing names, addresses, dates of birth, Social Security numbers, government identification numbers, financial account details, and health data, prompting the company to offer identity theft protection services and notify regulators and affected individuals.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On March 16 2026 CareCloud detected a temporary network disruption that affected one of its six electronic health record environments for approximately eight hours, after which functionality was restored. The company promptly reported the incident to law enforcement, notified its cyber insurer, and engaged third‑party cybersecurity experts to conduct a forensic analysis. A subsequent SEC filing disclosed that unauthorized access to the affected AWS environment had occurred between March 10 and March 16, and that the threat actor claimed to have exfiltrated data from databases stored there. CareCloud stated that it believed the threat actor no longer had access to its systems after the environment was secured and restored.
By June 24 2026 the investigation had confirmed that personal, financial, and medical information had been compromised, including names, addresses, dates of birth, Social Security numbers, driver’s license or other government ID numbers, financial account numbers, credit or debit card numbers, and medical and health insurance information, with a limited number of individuals also having full credit card details including CVV exposed. CareCloud noted that it had no evidence the stolen data had been misused. Based on filings with state attorneys general, at least 345,000 individuals were affected, including 270,197 Texas residents, and the company began mailing notification letters to those impacted while offering 24 months of complimentary identity theft protection services.
CareCloud engaged external cybersecurity experts to secure the affected environment, eliminate the threat, and verify that no persistent unauthorized access remained. The company reported that the incident was confined to its CareCloud Health division and did not affect other platforms, divisions, systems, data, or environments. Although CareCloud indicated that the breach had not had a material impact on its operations and that any potential losses should be covered by cyberinsurance, it acknowledged that remediation, response, legal, regulatory, and notification‑related expenses could arise and that the incident could affect patients, customers, counterparties, reputation, and ongoing operations. The organization stated that it would continue to strengthen the security of its systems to reduce the risk of similar incidents in the future. No ransomware group had publicly claimed responsibility for the attack as of the latest available information.
Sources
Sources available to members: 16 sources.