CareCloud, Inc.

Unauthorized access to a CareCloud EHR environment March 10–16 disrupted functionality and data access for about eight hours March 16 before restoration. Forensics confirmed exfiltration; HHS now reports 3,756,469 affected individuals, including a revised Texas filing identifying 270,529 Texans. Ransomware involvement and the responsible actor remain unresolved.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized access to systems, accounts, networks, or data.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Services remained available but with reduced performance, reliability, functionality, capacity, or responsiveness.
A specific application or software platform became unavailable or unusable.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
CareCloud experienced a confirmed cyber intrusion affecting one CareCloud Health electronic health record environment. The company’s March 27 SEC filing said an unauthorized third party partially disrupted functionality and data access for about eight hours March 16, 2026. A May 7 Form 10-Q said forensic analysis found that an undetermined amount of data was exfiltrated and that initial access occurred about one week before March 16.
The disruption was limited to one of CareCloud’s six EHR environments. The company restored all affected functionality and data access March 16 and said its other platforms, divisions and environments were unaffected. The public record does not identify particular hospitals, practices or patient-care episodes disrupted during the eight-hour outage.
The confidentiality impact was broader. The HHS breach-reporting portal lists 3,756,469 affected individuals for CareCloud, classified as a business associate, with a July 24 submission date and a hacking/IT incident involving a network server. That is the reported population, not proof that every affected provider or person has been identified. The Texas attorney general’s current filing, published Aug. 18, identifies 270,529 affected Texans. The earlier July reporting of at least 345,000 people nationally and 270,197 Texans has been superseded by these records. Texas lists names, addresses, Social Security numbers, government identification, financial, medical and health insurance information and birth dates; individual data involvement varies.
CareCloud first publicly disclosed the incident in its March 27 SEC filing after determining March 24 that the event was material. The filing confirmed unauthorized access and disruption but said data access or exfiltration remained under review. The May 7 filing converted that uncertainty into a forensic finding of exfiltration. CareCloud’s notification sample filed in California identifies March 10–16 as the unauthorized-access window in one AWS environment and June 24 as the date its review identified involved personal information. Those investigation dates do not extend the eight-hour operational disruption.
The incident is resolved. CareCloud said the event was contained March 16, all affected systems were restored and the intruder no longer had access. Later notifications document the continuing breach-response process, not renewed operational disruption.
Confidence is high that unauthorized access, an eight-hour disruption and data exfiltration occurred because CareCloud described each in SEC filings. Ransomware and attribution remain unresolved. Searches using CareCloud’s name and carecloud.com did not identify a stable victim claim, and no public source describes encryption, a ransom demand or a leak-site post.
Public sources do not establish the initial access vector, compromised identity, exploited vulnerability, malware family, exact database scope, whether the reported affected-person population will change, whether stolen information was published or every affected provider and patient location.

Somerset is the affected company's headquarters anchor, supported by the official notice's 7 Clyde Road address. Inclusion does not establish a facility-specific outage or locate the affected cloud environment.
CareCloud said an unauthorized third party disrupted one of six electronic health record environments for about eight hours on March 16, restoring access that evening while investigators assessed possible patient data exposure.
CareCloud reported that an unauthorized third party temporarily accessed one CareCloud Health EHR environment, causing about eight hours of partial functionality and data-access disruption before full restoration on March 16.
CareCloud said forensic analysis found that an undetermined amount of data was exfiltrated, that unauthorized access began about one week before March 16 and that all affected systems were fully restored.
Current official portal filtered CareCloud: 3,756,469 individuals; New Jersey business associate; July 24 submission; hacking/IT incident; network server. Submission date is not a verified revision date.
Official notification describes March 10–16 access to one AWS environment, June 24 identification of personal information and no unauthorized activity since March 16. Template does not identify every individual’s involved data.
The California attorney general record publishes CareCloud’s breach-notification sample and identifies March 10, 2026, as the start of the known breach period.
TechCrunch reported that breach filings in several states showed at least 345,000 affected people and that compromised information included medical, identity and financial data. It said no known ransomware group had publicly claimed the incident.
The current Texas AG CareCloud row identifies 270,529 affected Texans, notice by U.S. mail, and identity, financial, medical and insurance data categories.
The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.
The organization’s official website describes its identity, services, operating role and public or customer-facing programs.
Signed-in members can report an error, update, or missing source.