---
title: "CareCloud Health EHR data incident"
description: "Evidence-backed account of CareCloud Health EHR data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/carecloud-health-ehr-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/carecloud-health-ehr-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/carecloud-health-ehr-data-incident-2026/stix.json"
---

# CareCloud Health EHR data incident

An unauthorized third party accessed one of CareCloud Health's six electronic-health-record environments and caused an approximately eight-hour disruption. Later regulator reporting associated personal, financial, medical, and health-insurance information with the incident.

Last modified Aug 9, 2026 · 4 sources

## Summary

- **Environment:** Healthcare technology provider operating the affected EHR environment and reporting the population figures.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

An unauthorized third party accessed one of [CareCloud Health](https://carecloud.com/)'s six electronic-health-record environments and caused an approximately eight-hour disruption. [1](#source-1) [3](#source-3) [4](#source-4)

## Impact

Later regulator reporting associated personal, financial, medical, and health-insurance information with the incident. [3](#source-3)

Documented data types include:

- Driver's license numbers — Driver's-license numbers and other government-issued identifiers; reported by the Texas Attorney General and varying by individual. [3](#source-3)
- Financial account information — Financial-account information; the Texas field combines account and payment-card examples, and data varied by individual. [3](#source-3)
- Payment card information — Credit- or debit-card information; the Texas field combines account and payment-card examples, and data varied by individual. [3](#source-3)
- Names — Names; reported by the Texas Attorney General and varying by individual. [3](#source-3)
- Dates of birth — Dates of birth; reported by the Texas Attorney General and varying by individual. [3](#source-3)
- Contact information — Addresses; reported by the Texas Attorney General and varying by individual. [3](#source-3)
- Social Security numbers — Social Security numbers; reported by the Texas Attorney General and varying by individual. [3](#source-3)
- Health insurance information — Health-insurance information; reported by the Texas Attorney General and varying by individual. [3](#source-3)
- Clinical information — Medical information; reported by the Texas Attorney General and varying by individual. [3](#source-3)

A cited record reports 3,371,508 individuals (Overall individuals affected as reported in Texas Attorney General report BR-0005208; regulator-reported and not independently verified; as of 2026-07-28). [3](#source-3)

A cited record reports 270,197 individuals (Texas residents in report BR-0005208; a subset of the overall count and not additive; as of 2026-07-28). [3](#source-3)

The incident partially disrupted functionality and data access in one of six CareCloud Health EHR environments for approximately eight hours. [4](#source-4)

CareCloud believed the incident was limited to the CareCloud Health environment and did not affect its other platforms, divisions, systems, data, or environments. [4](#source-4)

As of the March 27 filing, CareCloud said the incident had not materially affected operations and was not reasonably likely to materially affect its financial condition or results, while the full impact remained undetermined. [4](#source-4)

CareCloud determined on March 24, 2026 that the incident was material because of the sensitivity of potentially affected information and possible consequences. [4](#source-4)

## Timeline

### March 10, 2026 — Activity began

Date of incident recorded on the California Attorney General page; the page does not state whether this was the first access, exfiltration, or another incident milestone. [1](#source-1)

### March 16, 2026 — Documented activity ended

CareCloud said it contained the incident and restored functionality on the day of discovery; this is not asserted as the end of every possible access or data-acquisition activity. [4](#source-4)

### March 16, 2026 — Discovery

Date CareCloud reported experiencing and discovering the network disruption. [4](#source-4)

### July 25, 2026 — Public disclosure

California Attorney General reported date for the submitted CareCloud sample notice; not asserted as the mailing date for every person. [2](#source-2)

### July 28, 2026 — Public disclosure

Publication date of Texas Attorney General report BR-0005208. [3](#source-3)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

CareCloud believed an unauthorized third party temporarily accessed the affected system. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [4](#source-4)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/carecloud-health-ehr-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Submitted Breach Notification Sample — CareCloud, Inc.

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-627090>

<a id="source-2"></a>

### Data Security Breach List — 2026 records

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/privacy/databreach/list>

<a id="source-3"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-4"></a>

### Current Report on Form 8-K — March 2026 cybersecurity incident

regulatory · CareCloud, Inc. · Mar 27, 2026

<https://www.sec.gov/Archives/edgar/data/1582982/000149315226013239/form8-k.htm>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Affected Organization · 100% confidence · current**  
   CareCloud patient and customer data exposure: CareCloud, Inc.
2. **Resulted In · 100% confidence · current**  
   March 2026 CareCloud Health EHR intrusion: CareCloud securities and breach notifications
3. **Exposed Data Category · 100% confidence · current**  
   CareCloud patient and customer data exposure: Driver's license numbers
4. **Exposed Data Category · 100% confidence · current**  
   CareCloud patient and customer data exposure: Financial account information
5. **Exposed Data Category · 100% confidence · current**  
   CareCloud patient and customer data exposure: Payment card information
6. **Resulted In · 100% confidence · current**  
   March 2026 CareCloud Health EHR intrusion: CareCloud patient and customer data exposure
7. **Affected Individual Count · 100% confidence · current**  
   CareCloud patient and customer data exposure: 3,371,508 individual
8. **Exposed Data Category · 100% confidence · current**  
   CareCloud patient and customer data exposure: Names
9. **Exposed Data Category · 100% confidence · current**  
   CareCloud patient and customer data exposure: Dates of birth
10. **Began At · 100% confidence · current**  
   March 2026 CareCloud Health EHR intrusion: 2026-03-10
11. **Exposed Data Category · 100% confidence · current**  
   CareCloud patient and customer data exposure: Contact information
12. **Resulted In · 100% confidence · current**  
   March 2026 CareCloud Health EHR intrusion: The incident partially disrupted functionality and data access in one of six CareCloud Health EHR environments for approximately eight hours.
13. **Exposed Data Category · 100% confidence · current**  
   CareCloud patient and customer data exposure: Social Security numbers
14. **Resulted In · 100% confidence · current**  
   March 2026 CareCloud Health EHR intrusion: CareCloud believed the incident was limited to the CareCloud Health environment and did not affect its other platforms, divisions, systems, data, or environments.
15. **Affected Individual Count · 100% confidence · current**  
   CareCloud patient and customer data exposure: 270,197 individual
16. **Ended At · 100% confidence · current**  
   March 2026 CareCloud Health EHR intrusion: 2026-03-16
17. **Resulted In · 100% confidence · current**  
   March 2026 CareCloud Health EHR intrusion: As of the March 27 filing, CareCloud said the incident had not materially affected operations and was not reasonably likely to materially affect its financial condition or results, while the full impact remained undetermined.
18. **Affected Organization · 100% confidence · current**  
   March 2026 CareCloud Health EHR intrusion: CareCloud, Inc.
19. **Disclosed At · 100% confidence · current**  
   CareCloud securities and breach notifications: 2026-07-25
20. **Exposed Data Category · 100% confidence · current**  
   CareCloud patient and customer data exposure: Health insurance information
21. **Discovered At · 100% confidence · current**  
   March 2026 CareCloud Health EHR intrusion: 2026-03-16
22. **Resulted In · 100% confidence · current**  
   March 2026 CareCloud Health EHR intrusion: CareCloud determined on March 24, 2026 that the incident was material because of the sensitivity of potentially affected information and possible consequences.
23. **Resulted In · 100% confidence · current**  
   March 2026 CareCloud Health EHR intrusion: CareCloud believed an unauthorized third party temporarily accessed the affected system.
24. **Disclosed At · 100% confidence · current**  
   CareCloud securities and breach notifications: 2026-07-28
25. **Exposed Data Category · 100% confidence · current**  
   CareCloud patient and customer data exposure: Clinical information

</details>
