CareCloud, a healthcare technology company serving more than 45,000 providers nationwide, has alerted at least 345,000 patients that their personal and medical records were compromised through a breach of its Amazon Web Services-hosted database. The incident occurred on March 16, 2026, when unauthorized access briefly interrupted one of CareCloud's six electronic health record systems for around eight hours.
According to the company, the breach was quickly contained and investigated with the help of a cybersecurity team from a Big Four accounting firm. CareCloud reported the event to its cybersecurity insurer and launched a forensic analysis to assess the scope and nature of the attack. The compromised data includes sensitive details like Social Security numbers, passports, driver’s licenses, bank account information, payment card numbers, and detailed health records.
Growing Healthcare Data Breaches in 2026
This breach is one of several in the healthcare sector this year, collectively exposing millions of patient records across various providers. Despite the scale, CareCloud has kept communication limited since its initial disclosure in March, and no ransomware group has claimed responsibility for the attack. The total number of affected individuals may rise as more states report incidents related to this breach. CareCloud has stated it holds sufficient cybersecurity insurance to cover potential losses stemming from this event.
This article offers informational content and does not serve as financial advice.



