The Wire
BusinessLaw & RegulationCybersecurityScience & Health

CareCloud says hackers stole patient records from one health data store

CareCloud says hackers stole patient records from one health data store
Photo: techcrunch.com

CareCloud is notifying patients after hackers stole records from one protected health data store.

Why it matters: The breach could affect patients across the U.S. and underscores the cyber risk in outsourced health records. It also puts pressure on providers and compliance teams that rely on third-party EHR operators.

  • TechCrunch reported CareCloud has begun notifying nearly 350,000 people.
  • CareCloud said unauthorized access hit one of its six electronic health record environments on March 16, 2026, disrupting it for about eight hours.
  • The company said the affected environment stores patient information and it was still assessing whether data was accessed or exfiltrated.
  • TechCrunch said the stolen data included names, addresses, Social Security numbers, government IDs, financial information, and medical and health-related information.

CareCloud began sending notices in late July after hackers stole medical records from one of its protected data stores, according to TechCrunch, which reported the breach affected nearly 350,000 people so far. Read TechCrunch's report.

In a March 27 SEC filing, CareCloud said the incident started on March 16, when unauthorized access disrupted one of its six electronic health record environments for about eight hours before systems were restored that evening. The company said it had determined on March 24 that the incident was material because of "the sensitivity of the potentially affected information" and likely response costs. See the SEC filing.

CareCloud said the affected environment stores patient information and that it was still assessing whether any data was accessed or exfiltrated, including the categories and volume of data. The company also said it engaged a cyber response advisory team from a Big Four accounting firm and reported the incident to law enforcement and its cyber insurer. Open the filing.

TechCrunch reported that notice filings said the stolen data included names, postal addresses, Social Security numbers, government-issued identification numbers, financial information, and medical and health-related information. It also said state attorney general listings showed at least 345,000 affected people across New Hampshire, Massachusetts, Texas and Maine. See the state filing roundup.

CareCloud stores patient records for more than 45,000 providers across the U.S., including doctors' offices, hospitals and other practices, making it a major health data processor. As of July 30, no publicly identified ransomware or extortion group had claimed responsibility, TechCrunch reported. Review the reporting.

By the numbers

  • nearly 350,000 - people TechCrunch said CareCloud had notified so far
  • 45,000+ - providers across the U.S. that use CareCloud's systems
  • 8 hours - length of the unauthorized access/disruption CareCloud disclosed

Yes, but: CareCloud has not publicly confirmed exactly what data was exfiltrated or the final total of affected individuals.

What's next: CareCloud is still assessing the scope of data access and exfiltration, and additional state notices could clarify the scale.

Based on reporting from

  • TechCrunch

See how this story touches your network - open The Wire in Jane.

Open in Jane