Summary
- Environment: Healthcare technology provider operating the affected EHR environment and reporting the population figures.
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
An unauthorized third party accessed one of CareCloud Health’s six electronic-health-record environments and caused an approximately eight-hour disruption. [1][3][4]
Impact
Later regulator reporting associated personal, financial, medical, and health-insurance information with the incident. [3]
Documented data types include:
- Driver’s license numbers — Driver’s-license numbers and other government-issued identifiers; reported by the Texas Attorney General and varying by individual. [3]
- Financial account information — Financial-account information; the Texas field combines account and payment-card examples, and data varied by individual. [3]
- Payment card information — Credit- or debit-card information; the Texas field combines account and payment-card examples, and data varied by individual. [3]
- Names — Names; reported by the Texas Attorney General and varying by individual. [3]
- Dates of birth — Dates of birth; reported by the Texas Attorney General and varying by individual. [3]
- Contact information — Addresses; reported by the Texas Attorney General and varying by individual. [3]
- Social Security numbers — Social Security numbers; reported by the Texas Attorney General and varying by individual. [3]
- Health insurance information — Health-insurance information; reported by the Texas Attorney General and varying by individual. [3]
- Clinical information — Medical information; reported by the Texas Attorney General and varying by individual. [3]
A cited record reports 3,371,508 individuals (Overall individuals affected as reported in Texas Attorney General report BR-0005208; regulator-reported and not independently verified; as of 2026-07-28). [3]
A cited record reports 270,197 individuals (Texas residents in report BR-0005208; a subset of the overall count and not additive; as of 2026-07-28). [3]
The incident partially disrupted functionality and data access in one of six CareCloud Health EHR environments for approximately eight hours. [4]
CareCloud believed the incident was limited to the CareCloud Health environment and did not affect its other platforms, divisions, systems, data, or environments. [4]
As of the March 27 filing, CareCloud said the incident had not materially affected operations and was not reasonably likely to materially affect its financial condition or results, while the full impact remained undetermined. [4]
CareCloud determined on March 24, 2026 that the incident was material because of the sensitivity of potentially affected information and possible consequences. [4]
Timeline
Activity began
Date of incident recorded on the California Attorney General page; the page does not state whether this was the first access, exfiltration, or another incident milestone.
[1]Documented activity ended
CareCloud said it contained the incident and restored functionality on the day of discovery; this is not asserted as the end of every possible access or data-acquisition activity.
[4]Discovery
Date CareCloud reported experiencing and discovering the network disruption.
[4]Public disclosure
California Attorney General reported date for the submitted CareCloud sample notice; not asserted as the mailing date for every person.
[2]Public disclosure
Publication date of Texas Attorney General report BR-0005208.
[3]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
CareCloud believed an unauthorized third party temporarily accessed the affected system. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [4]
