CareCloud disclosed that hackers breached an AWS environment tied to its CareCloud Health electronic health record platform and accessed a data store between March 10 and March 16, disrupting the environment before the company secured it. Breach notices filed with state attorneys general and subsequent reporting indicate the attackers claimed to have exfiltrated database data, with the incident affecting roughly 345,000 to 350,000 people in the United States.
The compromised information included names, addresses, dates of birth, Social Security numbers, driver’s license and other government ID numbers, bank account and payment card details, and medical and health insurance records. CareCloud said it engaged external cybersecurity experts, removed the threat, found no evidence of persistent unauthorized access, and is offering up to 24 months of identity theft protection and credit monitoring, while no ransomware or extortion group had publicly claimed responsibility at the time of reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On June 24, 2026, CareCloud determined that personal, financial, and medical information had been compromised in the incident. The exposed data included identifiers such as Social Security numbers, dates of birth, government ID numbers, payment card and bank account information, and health-related records.
CareCloud previously disclosed the incident on March 27, 2026. Early reporting indicated the compromised data storage was hosted on Amazon Web Services.
On March 16, 2026, the affected CareCloud environment was disrupted, marking the end of the known intrusion period. CareCloud later said it secured the environment, removed the threat, and found no persistent unauthorized access.
Hackers accessed an AWS environment tied to CareCloud Health's electronic health record data store between March 10 and March 16, 2026, and claimed to have exfiltrated data from databases. The compromised information included personal, financial, and medical data.
CareCloud filed breach notices with multiple state attorneys general disclosing that at least 345,000 to 350,000 people in the United States were affected. The notices said affected individuals would be offered up to 24 months of identity theft protection and credit monitoring.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcemalware.news
Open sourcedatabreaches.net
Open sourcesecurityweek.com
Open sourceteiss.co.uk
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.