On 16 March 2026, CareCloud Inc., the Somerset, New Jersey based healthcare technology company that provides electronic health record (EHR) storage, medical billing and revenue cycle services to more than 45,000 providers, detected unauthorised access to one of its six EHR environments hosted on Amazon Web Services. The intrusion had been running since 10 March. CareCloud restored the affected environment within eight hours of discovery and told the US Securities and Exchange Commission that the incident was material to its business. It did not say how the attacker got in, and five months on it still has not.
The unauthorised party had access to the environment for six days before detection. CareCloud has said the intruder exfiltrated data from databases inside it, but the company's public disclosures have never named an entry point: no phishing email, no vished phone call, no exploited vulnerability, no stolen employee credential is on record. The environment simply came under someone else's control, and it stayed that way for the better part of a week before anyone at CareCloud noticed.
The scale of what was taken has been revised upward every time CareCloud has been forced to disclose more. State attorneys general filings in July put the number at roughly 350,000 people. This week the tracker maintained by the US Department of Health and Human Services updated the figure to 3,756,469 individuals, a tenfold increase that HHS confirmed to reporters was accurate and not a clerical error. The stolen data includes names, addresses, dates of birth, Social Security numbers, driver's licence and other government identification numbers, financial account numbers, and medical and health insurance information. For a smaller subset of patients, the attackers also obtained full payment card numbers and CVV codes. It is now one of the five largest healthcare data breaches reported in the United States so far this year.
The defences that failed here were not weak by conventional standards. CareCloud operates six separate EHR environments, a segmentation strategy designed to contain exactly this kind of intrusion to a single compartment. It engaged outside cybersecurity specialists, restored the affected system within hours, and reported the incident to the SEC within the statutory window. None of that stopped six days of unsupervised access to a database holding the medical and financial records of millions of people, and none of it has produced a public account, even now, of how that access was obtained in the first place.
A cloud environment holding protected health information for millions of patients is a high impact asset, and any bulk read or export from it is an execution event. Under GoFirm, the moment a credential, valid or not, initiates that kind of access to the environment, a real time push notification goes to CareCloud's named security authority on their registered device. Biometric confirmation is required before the read proceeds. No confirmation, no data leaves the environment.
This holds regardless of how the credential was obtained. It does not matter whether it was phished, guessed, exposed in a misconfigured repository, or taken through a channel CareCloud has not yet identified. Whoever held that key, however they came to hold it, cannot produce a biometric confirmation on the named authority's own device through a separate channel. The execution boundary holds regardless of how the access was obtained.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.
References
1. Whittaker, Z. 2026. Health data giant CareCloud says hackers accessed patients' medical records. TechCrunch, 31 March 2026.
2. Arghire, I. 2026. CareCloud Data Breach Impacts Over 350,000. SecurityWeek, 31 July 2026.
3. Kovacs, E. 2026. CareCloud Data Breach Impact Grows to 3.7 Million Individuals. SecurityWeek, 19 August 2026.
4. Whittaker, Z. 2026. CareCloud confirms 3.7M patients had their medical records stolen in data breach. TechCrunch, 19 August 2026.
5. Toulas, B. 2026. Healthtech firm CareCloud data breach impacts 3.7 million patients. BleepingComputer, 19 August 2026.
Back to Blog
Case Studies·3 min read
The CareCloud breach grew tenfold in five months. Nobody has said how attackers got in.
By GoFirm
