CareCloud confirms cloud breach; patient data may be affected
CareCloud, a healthcare technology company, confirms hackers broke into one of its cloud computing environments and likely stole patient data. Potentially affected information includes names, addresses, Social Security numbers, birth dates, driver's license or government ID numbers, financial account numbers, medical and health insurance details, and, for some people, full payment card numbers with security codes.
- Report priority
- Medium
- Involves
- CareCloud Health
What is known
- CareCloud hasn't explained how the intruder first got in.
- The company confirms an unauthorized third party accessed one Amazon Web Services (AWS) environment used by its CareCloud Health division between March 10 and March 16, 2026, and the intruder claimed to have copied database data out of it.
- CareCloud discovered a network disruption on March 16, brought in outside cybersecurity experts, and secured the affected environment.
- On June 24, its review identified potentially affected information, including names, addresses, Social Security numbers, birth dates, driver's license or government ID numbers, financial account numbers, medical and health insurance information, and, for a limited number of people, complete payment card numbers with their security codes.
- CareCloud says it is unaware of identity fraud or improper use of personal information resulting from the incident.
What to do
If you haven't received a letter, or yours is unclear, ask your healthcare provider's privacy office whether your information is covered and which data fields were involved. A practice's privacy lead should confirm these details through its established CareCloud contact, using the filed CareCloud notice for context. Neither a CareCloud business relationship nor the absence of a letter settles whether your information was exposed.
Follow your own letter's enrollment code, deadline and protection offer at IDX enrollment. The filed template shows a December 17, 2026 deadline and a duration placeholder of 12 or 24 months; use the terms in your actual letter. Activate credit monitoring after enrollment and check your IDX account or ask IDX to confirm it's active. If your code fails, activation won't complete or you can't use online enrollment, call IDX enrollment support at 866-329-9984, Monday through Friday, 9 AM to 9 PM Eastern. The template leaves its general incident phone number blank. Take incident or scope questions to your provider's privacy office or the incident contact printed in your own letter. Review medical bills and insurance explanations of benefits, and report unfamiliar care or charges to your insurer or the named provider. If enrolled, report suspicious identity activity to IDX by phone or through its online request for help.
Reported details
CareCloud's account starts with unauthorized cloud access during March 10–16, 2026; how that access was obtained isn't disclosed. The intruder claimed to have copied data from databases in that environment. CareCloud investigated after the March 16 disruption and says it secured the environment, with no evidence of unauthorized activity since March 16.
CareCloud's filed notice confirms unauthorized access to a CareCloud Health AWS environment from March 10 to March 16, 2026, and says the intruder claimed to have copied database data. CareCloud hasn't disclosed the entry method. Its review identified the affected data types on June 24. SecurityWeek reports that these can include names, addresses, Social Security numbers, birth dates, driver's license or government ID numbers, financial account numbers, and medical and health insurance information.
For a limited number of people, complete payment card details, including security codes, were involved. Each recipient should check their own letter for the relevant fields. Early state filings identified at least 350,000 affected people; HIPAA Journal's August 18 update reports an HHS portal total of 3,756,469. CareCloud says it eliminated the threat, found no further unauthorized activity after March 16 and is unaware of misuse resulting from the incident.
HIPAA Journal reported no public claim of responsibility by a threat group as of August 18.
References
- oag.ca.gov · CareCloud_-_SSN_39739837v1.pdf company notice template enrollment and medical guidance
- app.idx.us · protect IDX enrollment letter code required