CareCloud Breach Hits 3.7M Healthcare Records
Healthcare IT firm CareCloud confirmed 3.7 million patients' data was exposed after an attacker spent eight hours inside one of its EHR environments.
3,756,469 patients. One attacker. Eight hours inside a live EHR environment.
CareCloud — a U.S. healthcare IT company that provides electronic health record (EHR) software to physician practices and health systems — filed breach notification documents with the Department of Health and Human Services (HHS) this week, confirming that scope. The attack occurred earlier in 2026; CareCloud disclosed publicly on August 19.
What’s Confirmed
Breach: Confirmed. CareCloud’s HHS filing is on record.
Scope: 3,756,469 individuals.
Access window: Approximately eight hours of unauthorized access to one of CareCloud’s EHR environments, per The Record.
Data categories exposed: Not publicly specified. Unconfirmed — treat as potentially including protected health information (PHI) until individual notification letters arrive.
Ransomware or extortion demand: Not reported by either source. No threat actor has publicly claimed responsibility as of August 20.
HIPAA Context
HIPAA’s Breach Notification Rule requires covered entities and their business associates to notify affected individuals within 60 days of discovering a breach, and to file with HHS for any incident affecting 500 or more individuals. CareCloud’s filing covers 3.75 million — roughly 7,500× that threshold.
Affected patients should expect written notification from their healthcare provider, not from CareCloud directly. CareCloud is a software vendor; the practices and health systems that license its EHR platform are the covered entities with the direct patient relationship and the HIPAA notification obligation.
What to Watch For
Individual notification letters will specify the data categories accessed and any remediation offers — credit monitoring, identity theft protection, that kind of thing. If you received care at a practice running CareCloud software and haven’t received a letter within 60 days of this disclosure, contact your provider directly.
Status as of August 20, 2026: breach scope confirmed by HHS filing; specific data categories and initial attack vector remain unconfirmed. BleepingComputer and The Record are the primary sources for this story.
Recent Breach Coverage
CareCloud joins a streak of confirmed data exposures across sectors:
- Scottish Crown Office Breach May Spread Across Agencies — sensitive criminal case files at risk
- France Confirms DGFIP Breach; Hacker Claims 600K — national tax authority
- SafePal Breach: 39,798 Customers’ Order Data for Sale — crypto wallet user data on sale
Found this useful? Share it.


