Technology

CareCloud Breach: 345,000 People's Medical and Personal Data Stolen

Martin HollowayPublished 12h ago5 min readBased on 5 sources
Reading level
CareCloud Breach: 345,000 People's Medical and Personal Data Stolen

CareCloud, a New Jersey-based electronic health records provider, has begun notifying hundreds of thousands of individuals that their personal and medical data was stolen in a breach discovered earlier this year. The incident affects at least 345,000 people across the United States, according to filings with the attorneys general of New Hampshire, Massachusetts, Texas, and Maine (TechCrunch).

Hackers had access to one of CareCloud's six patient data stores for six days, between March 10 and March 16, 2026. The breached store was hosted on Amazon Web Services. The company disclosed the incident to the U.S. Securities and Exchange Commission in a Form 8-K filing dated March 27, 2026, which states that CareCloud experienced unauthorized access on March 16 (SEC Filing). TechCrunch first reported on the breach on March 31, 2026.

CareCloud filed a data breach notice with the California Attorney General's office in the week of July 30, 2026. The California AG's data breach portal lists the breach date as March 10, 2026 and the report date as July 25, 2026 (California AG Portal). A hacker claimed to have exfiltrated data from CareCloud's databases, and the scope of stolen information is extensive: names, postal addresses, Social Security numbers, government-issued identification numbers including passport numbers and driver's license numbers, financial information including bank account and payment card numbers, and medical and health-related information.

As of July 30, 2026, no ransomware or extortion group had publicly claimed credit for the breach. CareCloud CEO Stephen Snyder did not respond to TechCrunch's request for comment. CareCloud stores patient records for more than 45,000 healthcare providers across the U.S., including doctors' offices, hospitals, and other medical practices.

The four-month gap between the SEC disclosure in late March and the state-level breach notifications in late July fits within the timeline allowed under HIPAA's Breach Notification Rule, which gives covered entities up to 60 days from discovery to notify affected individuals, with state-specific requirements adding further obligations. The California AG filing on July 25, more than 60 days after the March 16 access date, falls within the regulatory window but raises questions about how the 60-day clock was calculated — specifically, whether CareCloud counted from the date it first detected unauthorized access or from the date it confirmed that data had actually been removed from its systems.

The data categories involved here amount to a near-complete identity theft profile. Social Security numbers, financial account details, and government-issued ID numbers, combined with medical information, give a threat actor the raw material for synthetic identity fraud (where a criminal combines real and fabricated personal details to create a new, fraudulent identity), medical identity theft, and traditional financial fraud. Medical data is particularly valuable in illicit markets because it cannot be invalidated the way a compromised credit card can be reissued.

The architecture is worth noting. CareCloud maintains six separate patient data stores, and only one was breached, which suggests the company segmented its data across distinct storage environments and may have limited the damage. The breached store sat on AWS rather than on CareCloud's own on-premises infrastructure, which is not itself unusual — but it does mean the likely attack vector involved compromised credentials, misconfigured permissions, or exploited API access, rather than a network intrusion into CareCloud's own systems. The absence of a claimed ransomware or extortion group at this stage could indicate a data-only exfiltration operation, where the monetization path is resale on illicit markets rather than ransom negotiation.

For the 45,000-plus provider organizations whose patient data flows through CareCloud, the downstream impact is significant. Patients whose data was stolen face individual risk, but the providers themselves bear compliance and reputational exposure.

In this author's view, the incident reinforces a structural tension in healthcare technology. Centralizing patient records across tens of thousands of practices into a handful of shared platforms creates real operational efficiencies, but it also concentrates risk. A single breach at one electronic health records vendor can ripple across the patient bases of every practice that depends on it.

CareCloud has not publicly detailed the specific access vector, remediation steps taken since March, or whether the other five data stores were investigated for compromise. The company's SEC filing confirmed unauthorized access, but the full technical scope may not be clear until additional state filings or regulatory actions surface.