CareCloud, a cloud-based healthcare solutions provider, disclosed a data breach affecting 3.7 million individuals according to the United States Department of Health and Human Services breach tracker.
The company initially reported the incident in July, when state attorney general filings showed approximately 350,000 affected individuals. The HHS tracker updated this week revealed the actual scope was ten times larger.
The breach originated from a network intrusion in mid-March 2026. Threat actors gained access to one of CareCloud’s AWS environments between March 10 and March 16. The company discovered the compromise following a disruption to an electronic health record system. Investigators determined that attackers exfiltrated information from databases in the compromised environment, though the exact scope remained unclear until HHS calculations.
The stolen information includes names, addresses, Social Security numbers, driver’s license numbers, dates of birth, health insurance information, and medical records. For a limited subset of individuals, hackers also obtained full payment card information. This combination of data makes victims particularly vulnerable to identity theft and fraudulent charges.
No known cybercrime group claimed responsibility for the attack publicly. CareCloud has not disclosed whether the company paid ransoms or negotiated with attackers to prevent data sales on the dark web. The silence raises questions about whether data remains in criminal hands awaiting eventual disclosure.
The ten-fold discrepancy between initial reports and HHS tracker numbers initially raised suspicions of clerical error. HHS confirmed to SecurityWeek that the figure is accurate and reflects the most recent data provided by CareCloud to the agency. The delay between disclosure and full scope revelation suggests CareCloud continued discovering affected individuals as the investigation progressed.
CareCloud took to an official statement regarding the course of action, stating:
Upon discovering the incident, CareCloud quickly launched an investigation and took steps to contain and remediate the issue. CareCloud engaged external cybersecurity experts and, with their assistance, secured the affected environment, eliminated the threat, and confirmed that no persistent unauthorized access remained. CareCloud is continuing to strengthen the security of its systems and environments.
CareCloud faces potential regulatory fines, breach notification costs, legal liability from affected individuals, and reputation damage. Healthcare providers increasingly recognize that AWS infrastructure requires security monitoring equivalent to on-premise systems. Unfortunately for CareCloud, the compromise occurred despite cloud infrastructure supposedly providing advanced security controls.
