CareCloud, a New Jersey-based health technology firm, has confirmed a substantial data breach affecting approximately 345,000 individuals. The incident involved the unauthorized access of patient records, which were held within cloud-based systems hosted on Amazon Web Services (AWS). While the firm initially disclosed an incident in March, updated filings across various states have clarified the full scope and nature of the exposure.
According to Security Affairs, the unauthorized intrusion occurred over a six-day period, specifically between March 10 and March 16, 2026. During this timeframe, threat actors gained access to an electronic health record environment, claiming to have exfiltrated sensitive databases. The compromised information is extensive and highly sensitive, encompassing names, home addresses, Social Security numbers, and government-issued identification such as driver's licenses and passports. Furthermore, the breach exposed financial data, including bank account details and payment card information, alongside private medical and health records.
The scale of this incident highlights the significant security risks inherent in centralized healthcare data management, where a single breach can impact numerous medical providers and their patients across the United States. CareCloud serves a wide network of hospitals and clinics, providing essential services like revenue cycle management and electronic health records. Although the company has stated that there has been no evidence of persistent unauthorized access since mid-March, they have provided limited technical details regarding the specific methodologies used by the attackers. As of now, no specific threat actor group has officially claimed responsibility for the breach, and investigations into the extent of the impact continue as additional state-level filings are processed.
Reader Discussion & Insights