Cybercrime
,
Data Breach Notification
,
Data Privacy
CareCloud Said Compromise Involved One of Its AWS Cloud Environments
Cloud-based electronic health records vendor CareCloud is notifying nearly 3.8 million people that their personal and health information was potentially stolen in a March hacking incident involving one of its Amazon Web Services cloud environments.
See Also: OnDemand | Transform API Security with Unmatched Discovery and Defense
New Jersey-based CareCloud, which first reported the incident to the U.S. Securities and Exchange Commission in March, touts itself as providing artificial intelligence-powered health IT solutions to more than 40,000 healthcare providers in 70 medical specialties across all 50 states (see: Cloud-Based EHR Vendor Notified SEC About Hacking Incident).
The company, which generated $120.5 million in revenue in 2025, in a breach notice said that on March 16, it experienced a network disruption that affected one of its EHR environments.
The investigation into the incident determined that between March 10 and March 16, a threat actor accessed one of CareCloud’s AWS environments and claimed to have exfiltrated data from databases within that environment, the company said. As of March 16, there is no evidence of unauthorized activity within CareCloud’s environment, the firm said.
To date, no threat actor group appears to have taken responsibility for the hack.
Among the potentially affected information are patient names, addresses, dates of birth, Social Security numbers, driver’s license numbers, government ID numbers, financial account numbers, credit and debit card numbers, and medical and health insurance information.
The company said it is “continuing to strengthen the security of its systems and environments,” but it did not provide details.
Several national law firms have issued public statements in recent days and weeks saying they are investigating the CareCloud hack for potential class action litigation.
As of Wednesday, the CareCloud hack was ranked as the third-largest health data breach posted so far in 2026 on the U.S. Department of Health and Human Services’ HIPAA Breach Reporting Tool website.
The CareCloud hack is one of 166 other major health data breaches affecting a total of nearly 21.4 million people reported by third-party vendors to HHS so far this year.
In total, as of Wednesday the HHS website listed 425 major protected health information breaches that affected nearly 51.4 million people so far in 2026.
Click Here For The Original Source.
