CareCloud: a six-day cloud breach, disclosed five months later
A six-day intrusion into a CareCloud cloud environment in March 2026 has been
confirmed to affect 3.7 million patients β disclosed only in August,
through a federal regulatory filing. No attacker has claimed the breach.
β οΈ Read this before anything else. Unlike some
case files on this site, the breach is confirmed by the company itself, to a federal
regulator. What's less clear is everything around it: who did it, how long it took to
notice, and whether the final number has stopped moving.
The numbers, and their real status
6 days
Length of the intrusion into a CareCloud AWS environment, March 10β16, 2026. Confirmed.
HHS breach filing, reported 08/17β19/2026.
3.7M
Patients affected β a figure revised upward one day
after the initial disclosure.
CareCloud filing with HHS, 08/17β18/2026.
5 months
Time between the March intrusion and its public disclosure in August.
TechCrunch, 08/19/2026.
?
Attacker identity and ransom status. Neither is known or confirmed
at this stage.
As of 08/21/2026 β no group has claimed the attack.
Timeline
CONFIRMED
March 10β16, 2026
Threat actors gain access to one of CareCloud's AWS cloud
environments and remain inside for six days, extracting patient data.
CONFIRMED
August 17, 2026
CareCloud discloses the breach in a filing with the US
Department of Health and Human Services, making it the fifth-largest US healthcare
data theft reported so far in 2026.
CONFIRMED
August 18, 2026
The affected-patient count is revised upward, raising the
possibility that the final total could grow further. As of this page's publication, no
subsequent revision has been reported.
π₯Why this one matters beyond the number
CareCloud isn't a hospital β it's the electronic-records and billing infrastructure
behind tens of thousands of healthcare providers. A single cloud environment held data
on patients who never chose CareCloud directly; their own doctor's office did, on their
behalf. That's the structural risk of healthcare-tech vendors: the breach surface is one
company, the affected population is however many practices rely on it.
What was stolen
Names, addresses, Social Security numbers, driver's license numbers, dates of birth,
health insurance information, and medical/healthcare records. This is a materially
different risk profile from a phone number or an email address: it's enough, on its own,
to attempt identity theft, not just a convincing phone call.
π If you've received care through a provider that may use
CareCloud, the useful precaution goes beyond call screening: a credit freeze or fraud
alert with the major credit bureaus is a stronger response to SSN exposure than vigilance
alone. For the call-and-message side of what typically follows a healthcare breach, see
From Leak to Scam and
how Medusa links channels together.
Frequently asked questions
Is the CareCloud breach confirmed?
Yes. CareCloud confirmed it in a filing with the US Department of Health and Human
Services on August 17, 2026, revised upward the next day. This is a company disclosure
to a federal regulator, not a hacker's claim.
Who is behind the CareCloud breach?
Unknown. No cybercrime group has publicly claimed responsibility, and CareCloud has
not named a suspect or confirmed whether a ransom was paid.
What should CareCloud-linked patients do?
The stolen data includes SSNs, driver's license numbers, and insurance details β
enough to attempt identity theft. Beyond caution with unsolicited contact, consider a
credit freeze or fraud alert with the major credit bureaus.
π Last checked: August 21, 2026. This page will
be updated if the affected-patient count changes again, or if an attacker is identified.
Verifiable information to report: contact@egidio.app.
Cite this pageEgidio β The Threat Laboratory, "CareCloud: a six-day cloud breach, disclosed five months later," egidio.app/en/laboratoire/carecloud-us-health-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.