CareCloud, the New Jersey-based revenue-cycle and electronic health record vendor that serves more than 45,000 healthcare providers across all 50 states, has begun notifying hundreds of thousands of patients that hackers reached their medical records in a March 2026 intrusion. The company first flagged the incident in a March 24 SEC filing, per Prism News, but only determined on June 24 that protected health information was involved, according to a Massachusetts Attorney General notice cited in the same report. Impact figures currently in circulation range from "at least 345,000" (Zamin.uz, citing TechCrunch) to "nearly 350,000" (Tech Weekly) to "over 350,000" (SecurityWeek), and state filings suggest the count is not final.
What Happened
CareCloud has acknowledged since March that attackers got into one of its six patient data environments. What changed this week is the paperwork: breach notifications filed with the California Attorney General, plus filings referenced in New Hampshire, Massachusetts and Texas, put numbers and data categories on an incident the company had described only in broad terms.
The timeline is where the reporting genuinely diverges. Prism News says CareCloud told regulators the intruders were inside one of its six EHR environments for roughly eight hours on March 16, and that the affected environment was fully restored the same evening. Zamin.uz, summarising TechCrunch's reporting on the California filing, says unauthorised access to an electronic health record database ran for at least six days, from March 10 to March 16. Both accounts converge on March 16 as the end date and on a single repository being touched rather than the full estate. They do not agree on when the access started, and neither figure should be treated as settled. A separate commentary piece (aji18sushiny.com, unestablished outlet) repeats the eight-hour framing and adds that CareCloud engaged outside cybersecurity experts and believes the attacker no longer has database access; that last claim rests on a single low-tier source.
CareCloud also told regulators, per Zamin.uz, that the intruders claimed to have deleted or copied data from the repository. No ransom demand has been publicly confirmed, and as of publication no established ransomware or extortion crew has claimed the attack.
What Was Taken
The data categories described in the Massachusetts and California notifications, as reported by Prism News, are the worst combination for a healthcare victim: names, dates of birth, Social Security numbers, health insurance information and medical information. That single set spans identity theft, tax fraud, insurance fraud and medical identity misuse, and unlike a payment card it cannot be reissued.
Volume, again, depends on who you read. SecurityWeek headlines the incident at over 350,000 individuals. Tech Weekly puts it at nearly 350,000 "to date." Zamin.uz cites at least 345,000 and notes explicitly that filings in New Hampshire, Massachusetts and Texas indicate the figure may rise as review continues. The honest reading is a floor around 345,000 with the final tally still open. Set against CareCloud's book of business, that is a fraction of the millions of patient records the company holds for its 45,000-plus provider clients, which is consistent with the "one of six repositories" description but offers little comfort about what a broader compromise would have yielded.
Zamin.uz further reports, citing TechCrunch, that the compromised repository was hosted on third-party cloud infrastructure. The source text is truncated at the provider name, so we are not naming it here.
Why It Matters
This is the third significant hit on a US healthcare billing or revenue-cycle vendor in five months, and the pattern is now unmistakable. In March, revenue technology provider TriZetto disclosed exfiltration of personal and health records for over 3.4 million individuals. On July 20, UK-listed billing software firm Craneware told the London Stock Exchange that attackers had stolen customer, employee and partner records from systems serving thousands of US hospitals, clinics and pharmacies; Craneware's 2021 acquisition of pharmacy software maker Sentry brought it access to roughly 147 million patient records. HIPAA Journal, meanwhile, bundled CareCloud into a single week's roundup alongside Soniva Dental Care in Texas (up to 30,000 residents), Optalis Management Solutions in Michigan and Hudson Valley Medical Billing in New York.
The strategic point for defenders: attackers have worked out that the billing layer is a better target than the hospital. One revenue-cycle vendor aggregates records from thousands of covered entities, sits outside most hospital security programmes, and holds the exact identity-plus-clinical data mix that maximises extortion leverage. Compromising CareCloud is cheaper than compromising 45,000 medical practices individually.
The second lesson is the notification gap. If Prism News is right, the environment was restored on March 16 and the PHI determination did not land until June 24, roughly a hundred days later. That lag is where regulatory and litigation exposure accumulates: Edelson Lechtzin LLP announced a potential class action investigation on March 31, well before CareCloud had concluded PHI was involved, and other breach firms followed.
The Attack Technique
Initial access remains unstated. None of the available sources, including the SEC filing summary and the state AG notifications, describe an exploited vulnerability, a phishing vector, stolen credentials or a specific malware family. There is no named threat actor and no leak-site listing.
What can be inferred from the disclosures is limited but useful. The compromise was scoped to a single EHR data repository out of six, suggesting segmentation between environments held, or at least that the attacker did not pivot before being evicted. Detection and restoration happened on the same day the access ended, which points to a disruptive or noisy final stage rather than a quiet long-term implant. And the attacker's own claim to have "deleted or copied" data is the standard opening move of a double-extortion negotiation, whether or not a formal demand followed. Anyone modelling this incident should treat the intrusion vector as unknown rather than assuming a repeat of the TriZetto or Craneware tradecraft.
What Organizations Should Do
- Inventory every revenue-cycle, clearinghouse and EHR vendor that holds your patients' data, and record for each one whether they segment client data by environment and how many environments exist. CareCloud's six-repository split is the only reason this incident was 350,000 records instead of millions.
- Rewrite vendor contracts to impose a hard clock on breach notification and on the PHI-determination step specifically. A hundred days between containment and "your patients were affected" is a compliance failure you inherit, not one your vendor absorbs alone.
- Instrument bulk-read and bulk-export telemetry on any database holding PHI, including vendor-hosted ones where contractual access permits. Detect on volume anomalies against a baseline, not just on authentication events; six days of quiet access, if that account proves correct, is a query-pattern detection problem.
- Enforce phishing-resistant MFA and strict conditional access on every administrative path into hosted health data environments, and audit the cloud-provider identity layer separately from the application layer.
- Pre-stage your patient notification and credit-monitoring workflow now, on the assumption that a vendor will hand you a determination with no warning. Include SSN-specific guidance: fraud alerts and credit freezes at all three bureaus, plus IRS Identity Protection PIN enrolment, since tax fraud follows this data mix.
- Add insurance-claim monitoring to your patient guidance. Medical identity theft using stolen insurance details and clinical history is materially harder for victims to spot than card fraud, and standard credit monitoring will not surface it.
Sources: CareCloud Alerts Hundreds of Thousands Following Medical Record Bre... | CareCloud begins to notify hundreds of thousands after hackers stol... | CareCloud Data Breach Impacts Over 350,000 - SecurityWeek | Soniva Dental Care Data Breach Affects At Least ... | CareCloud Data Breach: Patient Data Compromised (2026) | CareCloud advierte sobre una filtración de datos médicos – Zamin.uz... | Craneware Investigates Data Breach Affecting US Healthcare Clients | CareCloud breach exposed patient data, including Social Security nu...