CareCloud Breach Exposes Over 350,000 Patients Records After Six-Day AWS Intrusion
The California filing details how an unauthorized third party accessed one of CareCloud’s Amazon Web Services (AWS) environments between March 10 and March 16. The attackers “claimed to have exfiltrated data from databases within that environment,” but no further activity has been detected since March 16. The breach remains limited to that six‑day window.
CareCloud’s data stores hold a wide range of patient information. The exposed records may include names, home addresses, Social Security numbers, government ID numbers such as passports and driver’s licenses, bank account details, payment‑card numbers, and extensive medical and health data. The combination of personal, financial and health information makes the data especially valuable to identity thieves and health‑insurance fraudsters.
The company’s profile underscores the potential reach of the compromise. CareCloud employs roughly 3,650 people and reported $120.5 million in revenue and $10.8 million in GAAP net income for fiscal year 2025. Its services are used by doctors’ offices, hospitals and other medical practices across the country, meaning that a breach of CareCloud’s data stores can affect the records of patients seen by those providers.
California’s data‑breach notification law requires companies to report incidents within 30 days of discovery. The state filing confirms that CareCloud complied with that requirement. It also notes that the breach involved an AWS environment, a fact that aligns with earlier reports from TechCrunch and other outlets that identified the breach as an AWS intrusion.
Other recent healthcare‑tech breaches have highlighted the sector’s vulnerability. In March, Cognizant’s TriZetto Provider Solutions disclosed a breach that affected 3.4 million people, and last week, billing‑software provider Craneware confirmed that hackers stole data from its hospital and pharmacy clients.
CareCloud’s delayed notification—four months after the initial admission—was largely due to the time needed to compile detailed information from state filings. The company began mailing notification letters in July, and the number of affected individuals is expected to rise as more disclosures are filed.
The breach raises questions about the security practices of cloud‑based health‑IT providers. CareCloud has not released technical details about how the attackers gained access to its AWS environment, and no hacker group has claimed responsibility.
Regulators and patients are watching closely. The California filing is the first public confirmation of the breach’s scope, and the state’s law requires affected residents to be notified. Other states may follow suit as their own filings become available.
At this time, CareCloud has not announced any remedial actions beyond the notification of affected individuals. The company’s insurance coverage for cybersecurity incidents has not been publicly disclosed.
The breach underscores the broader trend of increasing cyber‑attacks on healthcare data. With the sector’s reliance on cloud infrastructure, incidents that compromise AWS environments can have wide‑ranging impacts.
In summary, CareCloud’s March 2026 breach involved a six‑day intrusion into an AWS environment, exposed sensitive personal, financial and medical data for at least 350,000 patients, and prompted notifications under California’s data‑breach law. The company’s response has been limited to filing notices and mailing letters, and the total number of affected individuals is likely to rise as additional state filings are processed.
The incident remains a reminder of the importance of robust security practices for cloud‑based health‑IT services and the ongoing need for timely breach notifications under state law.