CareCloud, a healthcare information technology company, has reported a significant data breach affecting over 350,000 individuals. The breach, which occurred within the CareCloud Health division's electronic health record environment, was detected on March 16, 2026. Hackers accessed one of CareCloud's AWS environments between March 10 and March 16, extracting sensitive personal and financial data.
The compromised information includes names, addresses, Social Security numbers, dates of birth, driver's license numbers, government ID numbers, financial account details, credit and debit card numbers, and medical and health insurance information. For some individuals, full credit card details, including CVV numbers, were also exposed. Despite the breach, CareCloud has not found any evidence of misuse of the stolen data.
In response to the incident, CareCloud is offering affected individuals up to 24 months of free identity theft protection, credit monitoring, and ID theft recovery services. This package includes a $1,000,000 insurance reimbursement policy. CareCloud has collaborated with external cybersecurity experts to secure the affected systems and ensure the threat has been neutralized. The company continues to enhance the security of its environments.
While CareCloud has yet to disclose the total number of impacted individuals or identify the threat actors involved, the incident has been reported to various state Attorney General's Offices. Further updates will be provided as more information becomes available.


