Cyber & AI intelligence
Wasteland.
Briefs indexed2378
Issues26
Published Mondays07:30 CT
▣ Breach CARECLOUD-HEALTHCA 2026-09-03

CareCloud: Unattributed Six Day AWS Intrusion Exposing 3.75 Million Patients

"CareCloud, the Somerset, New Jersey based cloud EHR, practice management and revenue cycle management provider, has confirmed to federal regulators that a March 2026 intrusion into one of its Amazon Web Services…"

CareCloud, the Somerset, New Jersey based cloud EHR, practice management and revenue cycle management provider, has confirmed to federal regulators that a March 2026 intrusion into one of its Amazon Web Services environments exposed the protected health information of 3,756,469 people. That figure, now listed on the HHS Office for Civil Rights breach portal and reported consistently by TechCrunch, HIPAA Journal, SecurityWeek, Malwarebytes and Paubox, is roughly ten times the scale the company's own state attorney general filings had indicated only weeks earlier. TechCrunch describes it as the fifth largest theft of health data disclosed in 2026 so far. No threat group has claimed the attack, and CareCloud has not named one.

What Happened

The publicly reported timeline is consistent across sources. CareCloud detected a network disruption on March 16, 2026, affecting one electronic health record environment inside its CareCloud Health division. Malwarebytes reports the outage lasted roughly eight hours across one of the company's six EHR environments before service was restored that same evening, a detail only that source carries. CareCloud disclosed the incident to the SEC in March, with TechCrunch citing an initial regulatory disclosure dated March 27.

Third party incident responders determined that an unauthorized party had access to one of CareCloud's AWS environments from March 10 through March 16, 2026, a window of at least six days that predates detection. The threat actor claimed to have exfiltrated databases from that environment. CareCloud has not said how that claim was communicated; TechCrunch notes it is common for attackers to provide data samples alongside an extortion demand, but neither TechCrunch nor SecurityWeek is aware of any ransomware or leak site post taking credit. Paubox reports, citing BleepingComputer, that CareCloud referred the matter to law enforcement and engaged an outside cyber response team.

Data classification took far longer than containment. CareCloud confirmed the specific data types involved on June 24, 2026, roughly 100 days after discovery, and Paubox reports notification letters began going out on July 25.

The Numbers Do Not Agree, And That Matters

The victim count moved sharply, and the sources document a real progression rather than a dispute:

SecurityWeek explicitly flagged the tenfold jump as suspicious enough to look like a clerical error, and reports that HHS confirmed to them that the figure is accurate and reflects the most recent data supplied by CareCloud. SecurityWeek also notes the state AG entries still showed the older ~350,000 numbers at the time of writing, so anyone reconciling state filings against the federal portal will see a discrepancy that has not been retroactively corrected. TechCrunch says it is unclear whether the number will rise further.

Treat 3,756,469 as the current confirmed federal figure and the ~345,000 to ~350,000 range as a superseded early state level count, not a competing estimate.

What Was Taken

The exposed data varies by individual. Drawing on CareCloud's notification letter as filed with California and Massachusetts regulators and reported by SecurityWeek, HIPAA Journal, TechCrunch and Malwarebytes, the categories include:

SecurityWeek and Malwarebytes both report that for a limited subset of individuals the compromised data included full payment card details with CVV, which is the single most immediately monetizable element in the set. Paubox notes the version of the letter filed with California regulators went specifically to individuals whose Social Security numbers were involved, and that the same letter includes medical identity theft guidance covering explanation of benefits reviews and year to date service reports from insurers, which places clinical and coverage data squarely inside the affected categories.

CareCloud states it has no evidence the stolen data has been misused, and says in its notification letter that there has been no evidence of unauthorized activity in its environment since March 16, 2026. It is offering affected individuals up to 24 months of identity theft protection, credit monitoring and recovery services with a $1,000,000 insurance reimbursement policy.

Why It Matters

This is a supply chain event dressed as a single company breach. TechCrunch reports CareCloud stores patient records for more than 45,000 providers, and elsewhere describes tens of thousands of provider customers across the United States. Not one of those 3.75 million patients had a direct relationship with CareCloud. They saw a doctor. The aggregation of records at the RCM and EHR layer means a single misused cloud credential produces a victim population larger than most hospital systems will ever treat.

Three things should concern defenders specifically.

First, the dwell to disclosure gap. Access began March 10 and was only noticed on March 16 because it caused a visible service disruption. Detection was a side effect of an outage, not of monitoring. Then it took until June 24 to determine what was actually in the data, and until late July to begin notifying people. Victims spent four months unprotected against a combination of SSN, government ID and payment card exposure.

Second, the silence. HIPAA Journal notes that when a threat actor claims exfiltration and then no group ever posts the data or claims credit, it often indicates a ransom was negotiated, though it stresses CareCloud has not confirmed this. That is an inference, not a finding, and no source establishes payment. But it has a practical consequence: with no leak site, no group attribution and no published sample, downstream providers have no independent way to verify what left the environment. They are relying entirely on the victim company's own scoping.

Third, the accountability posture. TechCrunch reports that CEO Stephen Snyder did not respond to repeated requests for comment, including on whether the company paid, who owns security at the organization, and whether he intends to resign. CareCloud has not publicly commented on the attack since its March disclosure, and SecurityWeek noted at the time of its first report that the company had still not shared a total impact figure. For a publicly traded company that filed with the SEC in March and revised its federal victim count by more than an order of magnitude in August, that is a communications record worth noting.

The Attack Technique

Initial access remains undisclosed. What is established across sources is the shape of the intrusion, not its entry point.

The target was an AWS hosted electronic health record data store, one of six such environments, accessed by an unauthorized third party from March 10 to March 16. TechCrunch reports CareCloud later stated in breach notifications that the attackers exfiltrated data from its AWS account. No source identifies the initial vector, no CVE is named, and no malware or tooling is described. CareCloud has not disclosed whether credentials, a misconfigured storage resource, a compromised identity or an application flaw was involved, and no source establishes any of these.

The one defensive detail the company has offered is the remediation claim: CareCloud says it engaged external cybersecurity experts, secured the affected environment, eliminated the threat, and confirmed that no persistent unauthorized access remained. Notably, the blast radius appears to have been contained to a single EHR environment out of six, which suggests some degree of environment separation held. What did not hold was detection inside that environment during the six days the actor was operating in it.

Absent attribution or IOCs, there is nothing here to hunt on directly. The value is architectural, not tactical.

What Organizations Should Do

  1. Instrument cloud data stores for exfiltration, not just availability. CareCloud found this because something broke, six days in. Enable and centrally retain CloudTrail data events for S3 and equivalent object stores, alert on anomalous bulk read and cross account or external egress volume from database and backup buckets, and treat GuardDuty exfiltration findings as page worthy rather than ticket worthy.
  2. Assume your RCM and EHR vendor is your largest concentration of PHI risk. Inventory which third parties hold your patient records, in what cloud environments, and how those environments are segmented from one another. Ask specifically how many separate data stores exist and whether a compromise of one reaches the others, because in this case the answer to that question determined the difference between 3.75 million records and considerably more.
  3. Put contractual teeth on notification timelines. A 100 day gap between discovery and data type determination, then another month to letters, is a Business Associate Agreement failure as much as a security one. Require prompt initial notice, rolling scope updates, and forensic report access, not just a final figure filed with HHS.
  4. Reconcile vendor breach numbers against the HHS OCR portal directly. State AG filings in this incident still reflected the superseded ~350,000 count after the federal figure had risen past 3.7 million. If your vendor risk process is reading state filings only, your exposure estimate is stale by an order of magnitude.
  5. Harden identity in cloud environments holding PHI. Enforce phishing resistant MFA on all human and privileged access, eliminate long lived static access keys in favor of short lived role assumption, scope permissions to individual data stores rather than account wide, and run continuous least privilege review against unused permissions.
  6. Prepare patients for medical identity theft, not just credit fraud. The exposed combination supports insurance abuse as well as credit fraud. Direct affected individuals to review explanations of benefits, request year to date service reports from insurers, freeze credit with all three bureaus, and enroll in the offered 24 months of monitoring, while treating any unsolicited contact referencing their care as a probable phishing lure built on this data.

Sources: CareCloud confirms breach affects 3.75 million US patients, far mor... | CareCloud confirms 3.7M patients had their medical records stolen ... | CareCloud Data Breach Affects 3.75 Million Individuals | CareCloud begins to notify hundreds of thousands after hackers stol... | CareCloud Data Breach Impacts Over 350,000 - SecurityWeek | CareCloud Data Breach Impact Grows to 3.7 Million Individuals | Medical records, SSNs, and bank details exposed in CareCloud data b... | CareCloud notifies 3.7 million after six-day cloud intrusion