# Massive Data Breach at CareCloud Exposes Millions of Patient Records

*Published August 21, 2026*
*Source: [https://therecord.media/electronic-health-record-company-carecloud-data-breach](https://therecord.media/electronic-health-record-company-carecloud-data-breach)*

## Executive Summary

CareCloud experienced a data breach in March affecting 3.7 million patients after an intruder accessed its electronic health record environment. Sensitive information, including personal and financial data, was compromised, prompting CareCloud to notify federal authorities due to the incident's severity.

## Article

CareCloud, a major provider of healthcare technology and software, has reported a data breach affecting 3.7 million individuals. The breach occurred in March when an unauthorized intruder gained access to one of CareCloud's electronic health record environments for eight hours. Sensitive information, including personal details, Social Security numbers, identification numbers, credit and debit card data, as well as medical and insurance information, was compromised. CareCloud disclosed the breach to the Department of Health and Human Services and subsequently notified the Securities Exchange Commission due to the sensitive nature of the data involved. Affected individuals span multiple states, with significant numbers in Texas, South Carolina, and Oregon. However, the exact impact on states like New Hampshire, Massachusetts, and California remains unspecified. CareCloud, which supports over 45,000 healthcare providers and reported $120.5 million in revenue last fiscal year, has not attributed the breach to any known hacking group. This incident highlights the persistent threat faced by large electronic health record companies, which have become frequent targets of cyber attacks in recent years.
