CareCloud, a New Jersey-based health technology company, has confirmed a data breach affecting approximately 345,000 individuals, with the number potentially increasing as more state filings are processed. The incident involved unauthorized access to one of the company's electronic health record (EHR) data stores hosted on Amazon Web Services (AWS).
The breach occurred between March 10 and March 16, 2026, during which an unauthorized third party accessed a CareCloud AWS environment. The attacker claimed to have exfiltrated data from databases within this environment. CareCloud's investigation found no evidence of further unauthorized activity after March 16, 2026.
While CareCloud initially acknowledged a breach in March, the full scope and details, including the number of affected individuals, became public following recent disclosures to state attorneys general, such as California's. The company had remained largely silent on specifics for four months after its initial admission.
The compromised information may include sensitive personal and financial data. This potentially encompasses names, home addresses, Social Security numbers, government identification numbers (like passports and driver's licenses), bank account details, and payment card numbers. A significant volume of medical and health information was also exposed, making the breach particularly valuable to identity thieves and health insurance fraudsters.
CareCloud provides cloud-based EHR, medical practice management, revenue cycle management, billing, and AI-powered software to over 45,000 providers across the United States. The company, which employs approximately 3,650 people, reported $120.5 million in revenue and $10.8 million in GAAP net income for fiscal year 2025.
The company has not yet provided technical details regarding how the security breach occurred, and no group has publicly claimed responsibility for the attack. This incident follows other recent healthcare data breaches, including one affecting 3.4 million people disclosed by Cognizant’s TriZetto Provider Solutions in March, and another confirmed by billing software provider Craneware, which impacted its hospital and pharmacy clients.






