Major Healthcare Technology Firm Announces Data Breach
CareCloud, a major healthcare technology firm, has recently confirmed that hackers have breached parts of its network and gained access to patients’ medical records. CareCloud is a publicly traded healthcare information technology company that provides technology to streamline healthcare operations, enhance patient care, and help healthcare providers boost revenue. Its products include electronic health record software, and one of its six environments where patients’ electronic medical records are stored was accessed by a hacker. The hacker had access to that environment for around 8 hours before the access was detected and blocked.
While only one of its six electronic medical record storage environments was compromised, the breach is likely to be substantial, as CareCloud provides its software to more than 45,000 healthcare providers, including hospitals and physician practices. The data breach could therefore affect millions of Americans. At such an early stage of the investigation, the number of affected individuals is unknown.
CareCloud explained in a filing with the U.S. Securities and Exchange Commission (SEC) that it was able to restore its systems the same day that the intrusion was detected, and that a top four accountancy firm has been engaged to assist with the investigation. While unauthorized access to medical records was possible, it is currently unclear to what extent those records were accessed and the extent, if any, of data theft. CareCloud has confirmed that the hacker no longer has access to its environment, and CareCloud is working with cybersecurity experts to enhance security to prevent similar incidents in the future.
The intrusion was detected on March 16, 2026, which caused a temporary disruption to its CareCloud Health division, partially impairing the functionality of one of its electronic health record environments. A third-party accounting firm was engaged to perform cybersecurity work and assist with securing its environment, and to conduct a detailed forensic investigation to determine the nature and scope of the incident.
As a publicly traded company, CareCloud has a responsibility to notify its investors of any incidents that may have a material impact on its business; however, it was only determined on March 24, 2026, that the incident was significant enough to have a material impact on the business, hence the filing with the SEC. As of March 24, 2026, CareCloud said the breach is unlikely to affect its financial position, although CareCloud acknowledged that the investigation is still ongoing, so that may change.
Currently, no threat actor appears to have claimed responsibility for the incident, although it has only been a few days since the incident, so the lack of attribution at such an early stage is not unusual. CareCloud has not stated whether it has received a ransom demand, nor whether ransomware was involved.
