Monday, August 3, 2026

Policy & Regulation

CareCloud discloses data breach of patient health records

CareCloud disclosed a cyberattack where hackers accessed one of its digital medical chart environments for more than eight hours, though it is not known if data was exfiltrated.

CareCloud discloses data breach of patient health records
Photo: CareCloud

CareCloud, a healthcare technology company, has disclosed a data breach after hackers accessed one of its stores of patients’ electronic health records. In a regulatory filing, the company stated that unauthorized access was detected on March 16. According to the disclosure, hackers had access to this medical records storage for more than eight hours. CareCloud restored its systems the same day and believes the hackers are no longer in its network. To assist with the ongoing investigation, the company has called in an unspecified cybersecurity company to investigate the cyberattack.

The unauthorized access occurred in one of six environments where CareCloud stores patient medical and healthcare records. The company provides healthcare technology, including electronic health records storage, for more than 45,000 providers, including doctors and physicians at thousands of hospitals and medical practices, covering millions of patients. CareCloud has not disclosed how many individuals were affected by the breach. Additionally, it is not known if the hacker exfiltrated any data, or what types of data may have been stolen. It also remains unclear if the cyberattack resulted in any data destruction or if the hackers have contacted the company with any demands. Public internet records indicate that much of CareCloud’s files and data are hosted on Amazon Web Services.

CareCloud submitted its disclosure to the SEC (the US financial regulator) last Friday. The company determined on March 24 that the incident was significant enough to have a material impact on its business, legally requiring it to alert its investors. Although CareCloud stated that the breach is unlikely to affect the company’s financial position, it conceded that its investigation remains underway. A spokesperson for CareCloud did not respond to a request for comment regarding the incident or how the company structures patient data across its six environments.

The incident highlights the ongoing vulnerability of digital medical charts to cybercriminals, who frequently target healthcare technology providers to steal personal data and demand ransom. This cyberattack follows a pattern of high-profile security incidents in the sector, most notably the 2024 ransomware attack on Change Healthcare. That breach compromised a significant portion of America’s health records, leading to widespread system outages and delaying healthcare services across the country for months.

Why it matters

The breach of a major health technology provider highlights the ongoing vulnerability of digital medical chart systems to cybercriminals, following a 2024 ransomware attack on Change Healthcare.