Healthcare technology company CareCloud has confirmed that a data breach in March 2026 affected 3,756,469 people, according to a filing with the U.S. Department of Health and Human Services (HHS).
CareCloud is a publicly traded medical technology provider that offers electronic medical records, medical billing, practice management, and revenue cycle management services to healthcare organizations.
The company first disclosed the cybersecurity incident in a filing with the U.S. Securities and Exchange Commission (SEC) in March. CareCloud said the attack caused an approximately eight-hour network outage and blocked access to one of its databases.
CareCloud said the affected environment contained patient information, raising concerns that sensitive medical data may have been accessed or stolen.
The company launched an investigation to determine how the attackers gained access, what information was involved, and how many individuals were affected.
In a report submitted to the U.S. Department of Health and Human Services, CareCloud listed the number of people affected by the breach as 3,756,469.
CareCloud began mailing data breach notifications to affected individuals on July 25. The notices provide additional information about the incident and the company’s response.
The notification states that an unauthorized third party accessed one of CareCloud’s Amazon Web Services (AWS) environments between March 10, 2026, and March 16, 2026. The attacker allegedly claimed to have stolen data from databases hosted in that environment, according to the breach notification.
The sample notification submitted to authorities does not identify the specific types of information exposed beyond affected individuals’ full names. CareCloud has not publicly confirmed whether Social Security numbers, medical records, financial information, or other sensitive data were accessed.
Affected individuals are being offered 12 or 24 months of identity protection services through IDX. The services can be redeemed until December 17, 2026.
Because CareCloud provides technology and administrative services to healthcare organizations rather than directly treating patients, many people affected by the breach may be unfamiliar with the company.
Individuals who receive a notification should remain alert for phishing emails, text messages, and phone calls that use stolen information to appear legitimate. Avoid clicking suspicious links, verify unexpected requests independently, and consider using the identity protection services offered by CareCloud.
As of this writing, no ransomware group or data extortion operation has claimed responsibility for the CareCloud cyberattack.
BleepingComputer contacted CareCloud for additional information about the breach, the investigation, and the data involved. This article will be updated if the company provides further details.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




