The count of people caught in the CareCloud breach has grown by an order of magnitude. State attorney general filings through late July and early August put the total at roughly 345,000 to 350,000 individuals. This week the U.S. Department of Health and Human Services breach portal listed 3,371,508 on Monday and 3,756,469 on Tuesday. SecurityWeek, which spotted the revision, reported that HHS confirmed to it that the higher figure is accurate and reflects the most recent data CareCloud provided. State AG entries reportedly still showed the older numbers at the time of that reporting, so the public record currently carries two very different totals for the same incident.
One correction worth making up front: the incident is a March intrusion, not a July one. Attackers were inside a CareCloud AWS environment between March 10 and March 16, 2026. July and August are when the disclosure caught up.
What Happened
CareCloud, a Somerset, New Jersey provider of cloud-based EHR, revenue cycle management, practice management and clinical documentation software, detected a network disruption on March 16, 2026 affecting one of its electronic health record environments. TechCrunch reports the company runs six such patient data stores and serves more than 45,000 healthcare providers across the United States, which is what turns a single-environment compromise into a national-scale exposure.
Third-party cybersecurity experts were engaged. Their investigation determined that an unauthorized third party accessed one of CareCloud's AWS environments between March 10 and March 16, and that the actor claimed to have exfiltrated data from databases in that environment. The notice filed with California's attorney general states there is no evidence of unauthorized activity in the environment since March 16. CareCloud says it secured the environment, eliminated the threat, and confirmed no persistent unauthorized access remained.
Accounts differ on when the company first went to regulators. TechCrunch and Security Affairs describe an initial admission back in March, and TechNewsHub reports specifically that CareCloud disclosed the disruption in a late-March SEC filing dated March 27. SecurityWeek's later coverage frames the disclosure as arriving in early July. The most consistent reading across sources is a thin regulatory disclosure in late March followed by substantive detail only when state breach notices landed in late July.
The forensic milestones are firmer. June 24, 2026 is the date CareCloud says its investigation confirmed which data types were involved. Notification letters began going out around August 3, roughly five months after the intrusion window opened and about six weeks after the data was confirmed stolen. Aliteq and TechNewsHub both foreground that gap as the story's central failure. Two lower-tier sources, Aliteq and TechNewsHub, also report the March 16 disruption caused an outage of about eight hours before the environment was restored; that detail does not appear in the primary notification coverage.
No ransomware or extortion group has publicly claimed the attack. HIPAA Journal noted this held as of August 3, and TechCrunch and SecurityWeek report the same. CareCloud has not named an actor, and it is unknown whether a ransom was paid. The unclaimed-but-exfiltrated pattern, combined with an attacker who "claimed" theft directly to the victim, is consistent with a private extortion negotiation rather than a leak-site operation, though no source confirms that.
What Was Taken
The notification letter filed with the Massachusetts Office of Consumer Affairs and Business Regulation lists names, addresses, Social Security numbers, dates of birth, driver's license and government ID numbers, financial account numbers, credit and debit card numbers, and medical and health insurance information. For a limited subset of individuals, the compromised data also included full credit card details including CVV. CareCloud says exposure varies per individual, with specifics itemized in each letter, and that it has no evidence the stolen data has been misused.
TechNewsHub additionally lists passport numbers among the exfiltrated identifiers. No other source in this set includes passports, so treat that as unconfirmed.
On volume, the reported figures are:
- At least 345,000 individuals, including 270,197 Texas residents, per state AG summaries (HIPAA Journal, TechCrunch, Security Affairs)
- At least 350,000 individuals across several states' AG filings (SecurityWeek, July)
- 3,371,508 then 3,756,469 individuals on the HHS Office for Civil Rights portal (SecurityWeek, August, with HHS confirming the figure)
UNDERCODE NEWS carries a headline claiming the breach expanded "Beyond 37 Million People." Its own body text says more than 3.7 million and attributes that to prior reporting. The headline figure appears to be a decimal error and should not be cited.
The best available reading: the state-level numbers were partial jurisdictional counts filed before the review finished, and the HHS figure is the current company-supplied national total. The ten-fold jump was itself suspicious enough that SecurityWeek checked with HHS before running it.
Why It Matters
This is a supplier breach wearing a provider's clothes. Patients whose records were taken never had a relationship with CareCloud. Their doctors did. Every organization that outsources its EHR, billing or revenue cycle function inherits that vendor's blast radius without inheriting visibility into it, and the 45,000-provider figure is what converts one compromised AWS environment into millions of exposed people.
The data combination is the aggravating factor. SSN plus date of birth plus driver's license plus bank account plus payment card plus diagnosis and insurance detail is a complete synthetic identity kit with a medical fraud extension attached. Credit monitoring addresses maybe half of that. Medical identity abuse, which corrupts clinical records rather than credit files, has no equivalent remediation product.
The count revision is the operational lesson for anyone tracking third-party risk. If your vendor risk register recorded CareCloud at 345,000 in early August, it was wrong by a factor of ten by mid-August, and the state AG entries that many teams monitor had not caught up. HHS OCR portal figures are supplied by the covered entity and revised as investigations close; early state filings are jurisdictional slices, not totals. Treat any breach number issued before the forensic review completes as a floor.
The disclosure timeline also matters for anyone modeling notification risk. Intrusion March 10, detection March 16, exfiltration confirmed June 24, letters mailed August 3, national total published mid-August. Affected individuals had roughly five months of exposure before they could act, and CareCloud is offering up to 24 months of identity theft protection, credit monitoring and recovery services with a $1,000,000 reimbursement policy. HIPAA Journal reports that coverage is extended only where state law requires it.
The Attack Technique
The initial access vector has not been disclosed by CareCloud or established by any source. What is on the record is thin and worth stating plainly rather than embellishing.
The target was an AWS-hosted environment supporting one of CareCloud's EHR data stores, one of six per TechCrunch. Dwell time was at least six days, March 10 to March 16, and detection came from a service disruption rather than from security tooling, which suggests the intrusion was noticed because it broke something, not because it tripped an alert. The attacker's objective was database exfiltration, and the actor communicated an exfiltration claim to CareCloud. Neither SecurityWeek nor TechCrunch could establish how that claim was conveyed, though TechCrunch notes that sharing samples alongside a ransom demand is the common pattern. No credential theft, no exploited CVE, no misconfiguration and no lateral movement path has been named by any source. TechNewsHub attributes the forensic work to Big Four advisory teams; other sources say only "third-party cybersecurity experts."
Containment was reported as complete, with no persistent access, and the company says no unauthorized activity has been observed in the environment since March 16.
What Organizations Should Do
- Re-pull your third-party breach numbers from HHS OCR, not from state AG summaries. State filings are per-jurisdiction and lag the final count. If a vendor breach touches PHI, the OCR portal entry is the number that gets revised upward, and it can move by an order of magnitude months after the first press cycle.
- Ask cloud-hosting vendors for environment-level segmentation evidence. The relevant question for CareCloud-shaped suppliers is not "are you on AWS" but "how many customers' data sits in the single environment that would be compromised together, and what separates it from the other five." Get that in writing during renewal, not after an incident.
- Instrument detection so an intrusion is not first noticed as an outage. Detection here came via service disruption on day six. For cloud data stores specifically, alert on anomalous bulk read volume, unusual cross-account or cross-region access, CloudTrail gaps, new IAM principals and unexpected snapshot or export operations against production databases.
- Contractually pin notification timelines to the forensic milestone, not the mailing date. The June 24 to August 3 gap is where downstream providers lost the ability to warn their own patients. Require vendor notification within a defined window of confirmed exfiltration, with a specific named contact and interim updates.
- Plan remediation for the medical identity component, not just the credit one. For patients in a healthcare vendor breach, publish guidance on reviewing Explanation of Benefits statements, requesting medical record accounting of disclosures, and reporting insurance fraud. Credit monitoring does not detect a fraudulent claim filed under someone else's name.
- Assume payment card exposure requires separate handling. Full card data including CVV was taken for a subset here. If your organization's data flowed through the affected vendor, coordinate reissuance with your acquirer rather than relying on the vendor's generic identity protection offer.
Sources: CareCloud Data Breach Impact Grows to 3.7 Million Individuals - Sec... | CareCloud Notifies More Than 345000 Patients About ... | CareCloud begins to notify hundreds of thousands after ... | CareCloud Data Breach Impacts Over 350,000 - SecurityWeek | CareCloud Breach Exposes Medical and Financial Data of 345,000 - Se... | CareCloud AWS Breach Expands Beyond 37 Million People as Sensitive... | CareCloud notifies 345,000 patients months after breach exposed sen... | CareCloud Data Breach: 345,000 Patients Notified After Months-Long...