CareCloud disclosed that a March intrusion into one of its AWS-hosted electronic health record environments exposed the data of 3,756,469 individuals, sharply increasing the impact from earlier estimates of roughly 350,000. The company said attackers accessed the environment between March 10 and March 16 after a disruption led to the discovery of the incident in mid-March, and that the compromised databases contained personal information, insurance details, and medical records.
For a limited subset of affected individuals, the stolen data also included full payment card information, underscoring the severity of the breach for a healthcare technology provider serving more than 45,000 healthcare organizations. CareCloud said it engaged external cybersecurity experts, secured the affected environment, and reported no indication so far of misuse of the exposed data, while the U.S. Department of Health and Human Services confirmed the larger total on its healthcare breach tracker; no threat actor has been publicly identified, no group has claimed responsibility, and it remains unclear whether a ransom was demanded or paid.

See the actors and campaigns active against you right now.
10 events from the most recent confirmed update back to the earliest known activity.
CareCloud began distributing data breach notifications to affected individuals on July 25, 2026, after determining the incident affected 3,756,469 people. The company also offered 12 or 24 months of IDX identity protection services to eligible recipients.
In early July 2026, CareCloud disclosed the incident, and initial breach reports filed with several state attorneys general indicated that roughly 350,000 individuals were affected. Those early filings substantially understated the eventual scope later reported to federal regulators.
On June 24, 2026, CareCloud determined that the incident may have exposed individuals’ full names along with additional protected health information elements. This marked a later investigative finding about the scope of compromised data after the March intrusion.
Multiple class-action lawsuits alleging that personal information was compromised in the CareCloud breach were consolidated in federal court in Florida. This marked a legal escalation stemming from the incident.
CareCloud said it decided by March 24, 2026 to inform the U.S. Securities and Exchange Commission about the incident because of the sensitivity of the potentially affected information and the possible consequences. The company also said it initially reported the breach to law enforcement.
CareCloud said threat actors accessed one of its AWS-hosted electronic health record environments between March 10 and March 16, 2026. The attackers claimed to have exfiltrated databases containing personal, insurance, medical, and for a limited subset payment card data.
CareCloud disclosed that it detected the network intrusion in mid-March 2026 after a disruption involving an electronic health record environment. The company then launched an investigation and response effort.
Brookhaven ENT, Allergy, Aesthetics & Hearing disclosed that a data security incident at its third-party EHR provider CareCloud affected its patients. The provider reported at least 30,403 individuals impacted to HHS and said exposed data included names, dates of birth, email addresses, treatment details, medical record numbers, and appointment information.
On Tuesday, the HHS breach tracker updated the CareCloud incident to 3,756,469 affected individuals. HHS confirmed that this larger figure was accurate and reflected the latest data submitted by CareCloud.
The U.S. Department of Health and Human Services healthcare breach tracker listed the CareCloud incident as affecting 3,371,508 individuals on Monday. This reflected a much larger impact than the earlier state-level disclosures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
12 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourceitpro.com
Open sourcetechcrunch.com
Open sourceteiss.co.uk
Open sourcesecurityweek.com
Open sourceoag.ca.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.