BREAKING: CareCloud is notifying at least 350,000 people after hackers accessed an AWS EHR environment between March 10–16, 2026 and likely exfiltrated personal, financial, and medical data. Investigation confirmed compromise on June 24; multi-state AG filings support the ≥350k figure.
Canonical record: CareCloud AWS EHR breach.
What happened
CareCloud Health’s electronic health record stack was disrupted March 16, 2026. Forensics later showed unauthorized access to one of six EHR environments hosted on AWS from March 10 through March 16, with likely exfiltration. On June 24 the company concluded that personal, financial, and medical information was compromised.
Notification letters filed with Massachusetts OCABR and summarized by SecurityWeek list names, addresses, Social Security numbers, dates of birth, driver’s licenses and other government IDs, financial account numbers, credit/debit cards, and medical and health insurance information. For a limited set of people, full card data including CVV was also in scope per CareCloud’s incident notice. CareCloud says it has no evidence of misuse so far and is offering up to 24 months of identity protection.
State AG tallies underpin “at least 350,000” notified; CareCloud has not published a final national total in the coverage reviewed.
Who is at risk
Patients of practices that use CareCloud EHR/billing — you may receive a letter even if you never heard the brand name. Provider staff whose data sat in the same environment should watch workplace phishing.
Anyone whose notice lists card CVV should replace the card and enable bank alerts immediately.
Action items
- If you got a CareCloud letter, enroll in the offered monitoring using only the letter’s code.
- Freeze credit at all three bureaus if SSNs are listed.
- Review EOBs and pharmacy claims for services you did not receive.
- Replace cards if CVV/full PAN appears in your notice.
- Ignore “CareCloud refund” SMS and gift-card remediation scams.
- Ask your clinic whether they use CareCloud if you are unsure.
- Enable MFA on patient portals and email.
- Follow carecloudhealth.com/notice and AG letters — not Telegram screenshots.
Sources
Catalog; SecurityWeek; CareCloud notice; DataBreaches.
Timeline
March 10–16, 2026: unauthorized AWS EHR access. March 16: disruption/containment. June 24: compromise determination. July–August 2026: patient notices and ≥350k AG-facing tallies.
Cloud EHR blast radius
One vendor environment can span many clinics. That is why a CareCloud data breach surfaces as hundreds of thousands of patient letters even when most patients never chose CareCloud directly. Specialty practices should inventory which PHI lives in vendor AWS accounts and who can export it.
CVV exposure for a subset raises payment-fraud urgency beyond typical healthcare SSN notices. Treat those letters as card-compromise events.
FAQ
How many people? At least 350,000 per state filings; final national total may be higher.
What data? PHI/PII plus financial fields; limited full cards with CVV.
Was manufacturing or clinics offline nationwide? This was CareCloud’s EHR AWS environment — check your provider for local impact.
Bottom line
CareCloud’s March AWS EHR intrusion is now a confirmed ≥350,000-person notification event with SSNs, medical data, and card fields in scope. Enroll if notified; freeze credit; watch medical and card fraud.
Additional guidance for patients and clinics
Patients juggling multiple specialists should not assume one letter covers every CareCloud-connected practice. Keep each notice. Clinics should brief front desks that callers may claim to be “CareCloud breach remediation” and demand record numbers by phone — verify out-of-band.
Security teams at peer EHR vendors should tabletop anomalous AWS access spanning nearly a week before disruption is obvious. Six days of access is a long window for exfiltration.
Journalists should keep the ≥350,000 figure labeled as a lower bound from AG filings until CareCloud publishes a final census. Bookmark the BreachHistory CareCloud record for a stable summary.
Ignore gift-card demands and fake portals. Prefer the official notice page and mailed enrollment codes. Credit freezes and portal MFA beat panic clicks every time.
Providers should document which patients were notified and which data elements applied, because class-action inquiries will ask. Patients should record the date they enrolled in monitoring.
If you never receive a letter but your clinic confirms CareCloud use, ask the practice privacy officer whether your chart was in the affected AWS environment — do not email SSNs to random addresses to “check.”
Healthcare identity theft after EHR breaches often shows up as false claims months later. Keep watching EOBs through 2027 if your notice listed medical information.
CareCloud’s statement that systems were re-secured and persistent access removed is necessary but not sufficient for patients — the data already left. Act on the notice contents, not on containment language alone.
Finally, separate this 2026 CareCloud data breach from older unrelated CareCloud CA stubs or industry Change Healthcare outages when searching timelines.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.
Stay aligned with primary sources linked above, keep MFA enabled on related accounts, and treat unexpected payment or identity requests that cite this news cycle as fraud until verified through official channels you already trust. Organizations should brief support staff on social-engineering scripts and document decisions for auditors.