What You Need to Know about the CareCloud Data Breach

  • Published: Aug 22, 2026
  • Last Updated: Aug 22, 2026

CareCloud, Inc. is a publicly traded healthcare technology company headquartered in Somerset, New Jersey. The company provides electronic health records, medical billing, practice management, and revenue cycle services to more than 45,000 healthcare providers across the United States. Because it stores patient records and billing information on behalf of hospitals, doctors' offices, and other medical practices, CareCloud holds sensitive data belonging to millions of patients.

In March 2026, the company suffered a cyberattack that has now become one of the largest healthcare data breaches of the year. An unauthorized third party accessed one of CareCloud's Amazon Web Services environments, which hosted one of its six electronic health record systems, and claimed to have exfiltrated databases stored within it. In a filing with the U.S. Department of Health and Human Services in August 2026, CareCloud confirmed that the breach affected 3,756,469 individuals, making it the fifth largest theft of health data reported in 2026 so far.

The compromised data varies by individual and may include names, addresses, dates of birth, Social Security numbers, driver's license numbers, government ID numbers, financial account numbers, credit and debit card numbers, and medical and health insurance information. For a limited number of individuals, full payment card details, including the CVV security code, were also exposed.

CareCloud says it engaged external cybersecurity experts, secured the affected environment, eliminated the threat, and confirmed that no persistent unauthorized access remained. The company reported the incident to law enforcement and states there is no evidence of unauthorized activity in its systems since March 16, 2026. No ransomware group or extortion gang has publicly claimed responsibility for the attack. Affected individuals are being offered free identity theft protection and credit monitoring services through IDX.

When Was the CareCloud Data Breach?

According to CareCloud's investigation, an unauthorized third party had access to one of its AWS environments between March 10 and March 16, 2026. The intrusion caused a network disruption of about eight hours on March 16, cutting access to the affected database before the company fully restored the environment that evening. CareCloud disclosed the incident in late March through a filing with the U.S. Securities and Exchange Commission, describing it at the time as a temporary disruption with limited detail about patient data.

The company opened an investigation with a leading cyber response advisory team to determine the nature and scope of the incident. On June 24, 2026, the investigation confirmed that personal, financial, and medical information had been compromised. CareCloud began mailing notification letters to affected individuals in late July 2026, and filings with state attorneys general initially accounted for roughly 350,000 people.

The full scale only became clear months later. On August 17, 2026, CareCloud filed a report with the Department of Health and Human Services confirming that more than 3.75 million individuals were affected, a figure that was revised upward the following day. The dramatic increase from early state filings shows how significantly the known scope of a breach can change as an investigation identifies which records and individuals were involved.

CareCloud is offering affected individuals up to 24 months of complimentary identity theft protection through IDX, which includes credit and CyberScan monitoring, a $1,000,000 insurance reimbursement policy, and identity theft recovery services. The deadline to enroll is December 17, 2026.

How to Check If Your Data Was Breached

You may be affected by the CareCloud data breach if you received care from a hospital, doctor's office, or medical practice that uses CareCloud's electronic health record, billing, or practice management services. Since the company serves more than 45,000 providers nationwide, many patients may not recognize the CareCloud name even though the company stores their records.

CareCloud began mailing notification letters to impacted individuals in late July 2026. Look out for these official letters in your mail. The notification explains when the incident occurred, lists the specific types of your information that were involved, and includes an enrollment code for the complimentary IDX identity protection services. If you believe your information was involved but have not received a letter, contact CareCloud through the official contact information provided on its website or ask your healthcare provider whether it uses CareCloud's platform.

Even without a notification letter, certain warning signs may indicate your data was exposed. Watch out for bills for medical services you never received, unfamiliar claims on your explanation of benefits statements, unexpected password reset emails, or calls and messages from people claiming to be from CareCloud or your healthcare provider. Cybercriminals often use stolen information from data breaches to impersonate legitimate organizations and trick victims into revealing more details.

What to Do If Your Data Was Breached

If the CareCloud incident exposed your data, enroll in the free IDX identity protection services promptly. Visit https://app.idx.us/account-creation/protect and follow the enrollment instructions using the code provided in your notification letter. Remember that the monitoring must be activated to be effective, and only those who enroll before the December 17, 2026 deadline will benefit from these services.

Because Social Security numbers, financial account numbers, and payment card details were exposed for many individuals, consider placing a credit freeze or fraud alert on your credit file. A credit freeze restricts access to your credit report, making it difficult for anyone to open new accounts in your name. A fraud alert requires lenders to verify your identity before approving new credit requests. Both options are free and can be arranged with each of the three major credit bureaus.

You should also review your bank accounts, credit card statements, and credit reports closely for suspicious activity. Look out for charges you don't recognize, new accounts or loans you didn't open, and unfamiliar credit inquiries. If your payment card information was included in the breach, consider asking your card issuer to replace the card. Since medical and health insurance information was involved, review your explanation of benefits statements for services you never received and report any discrepancies to your insurer immediately.

Finally, be cautious of unusual or unsolicited messages that include suspicious links or attachments. Criminals may send phishing emails or make phone calls that appear to come from CareCloud, your healthcare provider, or your insurance company. Rather than disclose any sensitive information, contact these organizations directly using official contact details published on their websites.

Are There Any Lawsuits Because of the Data Breach?

Several law firms are actively investigating the CareCloud data breach for potential class action lawsuits, but no formal lawsuit has been filed against the company as of mid-August 2026. Edelson Lechtzin LLP, a national class action firm, announced an investigation seeking legal remedies for individuals whose sensitive personal data may have been compromised. Dapeer Law, P.A. is also investigating a potential class action on behalf of individuals whose personal and protected health information may have been exposed.

The investigations are evaluating whether affected individuals may have claims related to the increased risk of identity theft, failure to prevent unauthorized access, the four month gap between the intrusion and individual notification, and the exposure of highly sensitive medical, financial, and identity information. Attorneys note that accepting the free credit monitoring offered by CareCloud does not waive your right to participate in any future legal action.

Can My CareCloud Information Be Used for Identity Theft?

Yes, if your data was exposed in the breach. The combination of information stolen from CareCloud is particularly dangerous because it includes identity, financial, and medical records together. Criminals could use stolen Social Security numbers and dates of birth to open new credit accounts, apply for loans, file fraudulent tax returns, or commit other forms of financial fraud in your name.

Exposed financial account and payment card numbers could be used to make unauthorized charges, especially for the individuals whose full card details and CVV codes were compromised. Stolen medical and health insurance information could be used to obtain medical treatment or prescription drugs in your name, submit false insurance claims, or corrupt your medical records with someone else's information.

Additionally, criminals can use your stolen contact details to send convincing phishing emails or make phone calls that appear to come from CareCloud, your doctor's office, or your insurer. These messages often reference accurate personal details to appear legitimate. It is important to stay alert and act quickly if you notice anything suspicious to limit potential damage if your data is misused. Not everyone affected will become a victim of identity theft, but the risk remains long after the incident itself.

What Can You Do to Protect Yourself Online?

You can protect yourself online, reduce the risk of identity theft, and avoid online fraud by taking these steps:

  • Always watch out for phishing scams. Be cautious when opening links and attachments, even if a message looks convincing and appears to come from a trusted institution. Instead of clicking links in unsolicited messages, visit the official websites of those institutions or contact them directly on their published customer service numbers.
  • Use strong passwords for your online accounts. A strong password has at least 12 characters and contains a mix of numbers, lowercase and uppercase letters, and special characters. Create a different password for each account so that if one is compromised, attackers cannot access your other accounts.
  • Enable multi-factor authentication (MFA) wherever possible, especially on your bank, email, and patient portal accounts. Even if someone steals your password, they will not be able to access your accounts without passing a second form of verification.
  • Monitor all activity on your financial accounts, including bank accounts, credit cards, and credit reports. Read your statements closely for suspicious transactions, no matter how small, and report unfamiliar charges immediately. You can set up real-time transaction alerts on your banking apps for prompt notifications.
  • Check your credit reports regularly for unfamiliar inquiries or accounts. Consider placing a credit freeze or fraud alert if your Social Security number was stolen in a data breach. This makes it harder for anyone to open new accounts in your name.
  • Review your explanation of benefits statements and medical records periodically for services you never received. Report any discrepancies to your insurer or healthcare provider right away.
  • Keep your software and internet devices up to date, and protect your computer with anti-virus software and a firewall. Enable automatic updates so your devices install security patches as soon as they are released.
  • Sign up for identity theft protection services for additional peace of mind. These services work preemptively by alerting you when your data is leaked before any damage is done.

Related Articles

What is Data Leak and How to Prevent Accidental Data Leakage

Data breaches take many forms, and one of them is through data leak and accidental web exposure. M ... Read More

The Saga of T-Mobile Data Breach: 2013, 2015, 2021 and 2023 Hacks

T-Mobile has experienced a number of data breaches in the past decade. The first case occurred som ... Read More

Anthem Data Breach Exposed 78 Million Records

In the Anthem Data Breach of 2015, hackers were able to steal 78.8 million member’s records. ... Read More

Everything You Need to Know About Insider Data Breach

Data breaches are on the news frequently, but the average person doesn’t really know that much a ... Read More

The NSA Hack, How Did it Happen?

The National Security Agency (NSA) was the main attraction in a major data breach involving three ... Read More

Latest Articles

What You Need to Know about the Microsoft Azure Employee Data Breach

What You Need to Know about the Microsoft Azure Employee Data Breach

A threat actor using the alias TheHatman is selling employee databases allegedly stolen from the Microsoft Azure cloud environments of some of the world's largest companies.

What You Need to Know about the CareCloud Data Breach

What You Need to Know about the CareCloud Data Breach

CareCloud, Inc. is a publicly traded healthcare technology company headquartered in Somerset, New Jersey. The company provides electronic health records, medical billing, practice management, and revenue cycle services to more than 45,000 healthcare providers across the United States.

What You Need to Know about the Medtronic Data Breach

What You Need to Know about the Medtronic Data Breach

Medtronic Plc is an American-Irish medical device company founded in 1949. As one of the largest medical device companies in the world and with over 90,000 employees, the company operates in about 150 countries.

What You Need to Know about the Novo Nordisk Data Breach

What You Need to Know about the Novo Nordisk Data Breach

Novo Nordisk is a leading global healthcare company headquartered in Denmark with production facilities in two other countries.

What You Need to Know about the Carnival Data Breach

What You Need to Know about the Carnival Data Breach

Headquartered in Doral, Florida, Carnival Corporation is one of the world's largest cruise operators, with a fleet of more than 90 ships visiting over 800 ports and destinations.

What You Need to Know about the Charter Communications Data Breach

What You Need to Know about the Charter Communications Data Breach

Widely known through its Spectrum brand, Charter Communications is one of the largest broadband and cable service providers in the United States.

Featured Articles

How to Buy a House with Bad Credit

How to Buy a House with Bad Credit

Buying your own home is the American Dream, but it might seem out of reach to those with bad credit. However, the good news is, if your credit is less than perfect, you do still have options and in most cases, can still buy a home.

How Secure Is Your Password? Tips to Improve Your Password Security

How Secure Is Your Password? Tips to Improve Your Password Security

Any good IT article on computers and network security will address the importance of strong, secure passwords. However, the challenge of good passwords is that most people have a hard time remembering them, so they use simple or obvious ones that pose a security risk.

Top 10 Senior Scams and How to Prevent Them

Top 10 Senior Scams and How to Prevent Them

Senior scams are becoming a major epidemic for two reasons. First, seniors often have a lot of money in the bank from a life of working hard and saving.

Notice

By proceeding with this scan, you agree to let IDStrong run a Free Scan of supplied parameters of your personal information and provide free preliminary findings in compliance with our Terms of Use and Privacy Notice. You consent to us using your provided information to complete the Free Scan and compare it against our records and breach databases or sources to provide your Free preliminary findings report.

Rest assured: IDStrong will not share your information with third parties or store your information beyond what is required to perform your scan and share your results.

Free Identity Threat Scan
Instantly Check if Your Personal Information is Exposed
All fields below are required
Please enter first name
Please enter last name
Please enter a city
Please select a state
Please enter an age
Please enter an email address
Close