Skip to content
feed: live
>_0dayNews
threat intel
● Breaking

CareCloud Breach Hits 3.7M Healthcare Records

Healthcare IT firm CareCloud confirmed 3.7 million patients' data was exposed after an attacker spent eight hours inside one of its EHR environments.

airgapMorgan "airgap" Reyes·Published ·2 min read

3,756,469 patients. One attacker. Eight hours inside a live EHR environment.

CareCloud — a U.S. healthcare IT company that provides electronic health record (EHR) software to physician practices and health systems — filed breach notification documents with the Department of Health and Human Services (HHS) this week, confirming that scope. The attack occurred earlier in 2026; CareCloud disclosed publicly on August 19.

What’s Confirmed

Breach: Confirmed. CareCloud’s HHS filing is on record.

Scope: 3,756,469 individuals.

Access window: Approximately eight hours of unauthorized access to one of CareCloud’s EHR environments, per The Record.

Data categories exposed: Not publicly specified. Unconfirmed — treat as potentially including protected health information (PHI) until individual notification letters arrive.

Ransomware or extortion demand: Not reported by either source. No threat actor has publicly claimed responsibility as of August 20.

HIPAA Context

HIPAA’s Breach Notification Rule requires covered entities and their business associates to notify affected individuals within 60 days of discovering a breach, and to file with HHS for any incident affecting 500 or more individuals. CareCloud’s filing covers 3.75 million — roughly 7,500× that threshold.

Affected patients should expect written notification from their healthcare provider, not from CareCloud directly. CareCloud is a software vendor; the practices and health systems that license its EHR platform are the covered entities with the direct patient relationship and the HIPAA notification obligation.

What to Watch For

Individual notification letters will specify the data categories accessed and any remediation offers — credit monitoring, identity theft protection, that kind of thing. If you received care at a practice running CareCloud software and haven’t received a letter within 60 days of this disclosure, contact your provider directly.

Status as of August 20, 2026: breach scope confirmed by HHS filing; specific data categories and initial attack vector remain unconfirmed. BleepingComputer and The Record are the primary sources for this story.

Recent Breach Coverage

CareCloud joins a streak of confirmed data exposures across sectors:

Found this useful? Share it.