
CareCloud Data Breach (3.4 Million People Affected)
The CareCloud data breach affected 3,371,508 people in unauthorized access between March 10 and 16, 2026 involving health, identity, and financial information.
The incident affected one of six electronic health-record environments in the CareCloud Health division. The company restored the systems the same day; a later investigation found that a third party accessed an AWS environment and claimed to have removed data.
What Happened in the CareCloud Breach?According to the official Massachusetts consumer notice, unauthorized access began on March 10 and ended when CareCloud detected a network disruption on March 16, 2026. The company engaged external cybersecurity specialists, secured the environment, and notified law enforcement.
CareCloud's SEC Form 8-K says the disruption lasted about eight hours in one electronic health-record environment and did not affect its other platforms. Public documents do not identify the initial access method or vulnerability.
What Information Was Affected?The Texas Attorney General lists names, addresses, Social Security numbers, driver's-license and government-identification information, financial and credit or debit card information, medical information, health-insurance information, and dates of birth.
Data fields can differ by person and should not be assumed to apply to everyone. Notice recipients should rely on the scope stated in their own letters.
How Many People Were Affected?Texas Attorney General record BR-0005208 reports 3,371,508 affected people across the United States, including 270,197 Texas residents. The Texas figure is included in the nationwide total and is not added separately.
What Should Affected People Do?People whose Social Security, government-identification, or financial information was affected can review credit reports, new-account applications, and bank activity and consider a free credit freeze or fraud alert.
People whose medical or health-insurance information was affected should review insurance explanations, patient portals, and unfamiliar service claims. Unexpected links using the name of CareCloud, a healthcare provider, or an insurer should be verified independently; do not share passwords, verification codes, or identity details.