Egidio
Case file Β· August 21, 2026

CareCloud: a six-day cloud breach, disclosed five months later

A six-day intrusion into a CareCloud cloud environment in March 2026 has been confirmed to affect 3.7 million patients β€” disclosed only in August, through a federal regulatory filing. No attacker has claimed the breach.

⚠️ Read this before anything else. Unlike some case files on this site, the breach is confirmed by the company itself, to a federal regulator. What's less clear is everything around it: who did it, how long it took to notice, and whether the final number has stopped moving.

The numbers, and their real status

6 days
Length of the intrusion into a CareCloud AWS environment, March 10–16, 2026. Confirmed.
HHS breach filing, reported 08/17–19/2026.
3.7M
Patients affected β€” a figure revised upward one day after the initial disclosure.
CareCloud filing with HHS, 08/17–18/2026.
5 months
Time between the March intrusion and its public disclosure in August.
TechCrunch, 08/19/2026.
?
Attacker identity and ransom status. Neither is known or confirmed at this stage.
As of 08/21/2026 β€” no group has claimed the attack.

Timeline

CONFIRMED
March 10–16, 2026
Threat actors gain access to one of CareCloud's AWS cloud environments and remain inside for six days, extracting patient data.
CONFIRMED
August 17, 2026
CareCloud discloses the breach in a filing with the US Department of Health and Human Services, making it the fifth-largest US healthcare data theft reported so far in 2026.
CONFIRMED
August 18, 2026
The affected-patient count is revised upward, raising the possibility that the final total could grow further. As of this page's publication, no subsequent revision has been reported.

πŸ₯Why this one matters beyond the number

CareCloud isn't a hospital β€” it's the electronic-records and billing infrastructure behind tens of thousands of healthcare providers. A single cloud environment held data on patients who never chose CareCloud directly; their own doctor's office did, on their behalf. That's the structural risk of healthcare-tech vendors: the breach surface is one company, the affected population is however many practices rely on it.

What was stolen

Names, addresses, Social Security numbers, driver's license numbers, dates of birth, health insurance information, and medical/healthcare records. This is a materially different risk profile from a phone number or an email address: it's enough, on its own, to attempt identity theft, not just a convincing phone call.

πŸ”’ If you've received care through a provider that may use CareCloud, the useful precaution goes beyond call screening: a credit freeze or fraud alert with the major credit bureaus is a stronger response to SSN exposure than vigilance alone. For the call-and-message side of what typically follows a healthcare breach, see From Leak to Scam and how Medusa links channels together.

Frequently asked questions

Is the CareCloud breach confirmed?

Yes. CareCloud confirmed it in a filing with the US Department of Health and Human Services on August 17, 2026, revised upward the next day. This is a company disclosure to a federal regulator, not a hacker's claim.

Who is behind the CareCloud breach?

Unknown. No cybercrime group has publicly claimed responsibility, and CareCloud has not named a suspect or confirmed whether a ransom was paid.

What should CareCloud-linked patients do?

The stolen data includes SSNs, driver's license numbers, and insurance details β€” enough to attempt identity theft. Beyond caution with unsolicited contact, consider a credit freeze or fraud alert with the major credit bureaus.

πŸ“Œ Last checked: August 21, 2026. This page will be updated if the affected-patient count changes again, or if an attacker is identified. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio β€” The Threat Laboratory, "CareCloud: a six-day cloud breach, disclosed five months later," egidio.app/en/laboratoire/carecloud-us-health-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.