News
CareCloud Breach Highlights the Risks Behind Healthcare's Cloud Infrastructure
- By John K. Waters
- 08/19/2026
A recent data breach at healthcare technology company CareCloud is drawing attention to the amount of sensitive patient information concentrated in the cloud systems and technology vendors that increasingly support healthcare delivery.
CareCloud first disclosed the incident in a March 27 filing with the U.S. Securities and Exchange Commission, stating that a March 16 network disruption affected one of six electronic health record environments in its CareCloud Health division for about 8 hours.
At the time, the company said the incident had been contained and that investigators were still working to determine whether patient information or other data had been accessed or exfiltrated. CareCloud nevertheless classified the incident as material because of the sensitivity of the potentially affected information and the possible legal, regulatory, and operational consequences.
The picture became clearer months later.
According to breach notifications cited by TechCrunch and SecurityWeek, investigators determined that an unauthorized party had access to one of CareCloud's Amazon Web Services environments from March 10 through March 16. The attacker claimed to have exfiltrated information from databases in that environment.
CareCloud determined on June 24 that personal, financial, and medical information had been compromised.
The California attorney general's breach database lists CareCloud's incident as beginning March 10 and shows the company's notification filing dated July 25.
Massachusetts regulators reported that 72,102 residents of that state were affected. The state's 2026 breach report indicates that compromised information included Social Security numbers, medical records, financial account information, driver's license information, and credit or debit card numbers.
TechCrunch reported in late July that state disclosures showed at least 345,000 people had been affected across the United States. Subsequent state reporting has produced differing totals, making the precise nationwide number difficult to establish from the available public filings.
More Than an Eight-Hour Outage
The CareCloud incident illustrates the difference between the immediate operational effects of a cyberattack and the scope that can emerge after a forensic investigation.
CareCloud's initial SEC filing focused on an approximately eight-hour disruption to one EHR environment. The company's subsequent notifications indicated that the unauthorized party had been present in the AWS environment for 6 days.
That distinction matters for healthcare organizations whose clinical systems depend on cloud-hosted applications and outside technology providers.
An interruption may last hours, while the security investigation needed to identify what an attacker accessed, determine which records were involved, and identify affected individuals can take months.
CareCloud said in March that the event appeared to be confined to the affected CareCloud Health environment and that its other platforms, divisions, systems, and environments were not affected. The company also said it engaged an outside cyber response team associated with a Big Four accounting firm and began a forensic investigation.
CareCloud has not publicly identified the initial method used to gain access to the environment, and no known ransomware or extortion group had publicly claimed responsibility for the incident as of its July 30 report.
That leaves important questions about the intrusion unanswered.
Healthcare Vendors Remain Part of the Attack Surface
CareCloud is not an isolated example of sensitive health information being exposed through a healthcare technology provider or business associate.
The U.S. Department of Health and Human Services' Office for Civil Rights breach portal, which lists reported breaches affecting 500 or more people, continues to show hacking incidents involving healthcare providers and their business associates.
Recent entries include Unlimited Technology Systems, a business associate that reported a July breach affecting more than 3.8 million people, and Xsolis, another business associate that reported a hacking incident involving a network server affecting nearly 1.4 million people.
Other recent reports on the HHS portal include MCBS, a business associate reporting more than 1.2 million affected individuals, and Operation PAR, which reported a hacking incident affecting more than 145,000 people. In each case, HHS lists a network server as one of the locations of the compromised information.
Those entries do not necessarily involve the same attack methods, infrastructure, or security failures as CareCloud. They do, however, show that healthcare organizations face exposure not only through their own systems but also through companies that handle data or provide technology on their behalf.
The HHS portal categorizes many of the incidents currently under investigation as "Hacking/IT Incident," with network servers frequently listed as the location of the breached information.
Cloud Hosting Does Not Transfer Security Responsibility
The CareCloud incident also illustrates an important distinction in cloud security.
The fact that compromised information was hosted in an AWS environment does not, by itself, indicate that Amazon Web Services was breached.
Public disclosures reviewed so far say an unauthorized party gained access to CareCloud's AWS environment. They do not identify a compromise of AWS infrastructure itself.
That difference is important for healthcare organizations evaluating cloud risk. Cloud providers supply infrastructure and security capabilities, but healthcare organizations and their technology vendors still determine how applications, accounts, data, and permissions are configured and managed within those environments.
In CareCloud's case, the company has not publicly disclosed enough information to determine how the attacker obtained access or which security control failed.
The incident, therefore, does not provide evidence of a particular technical lesson, such as a failure of multifactor authentication, a software vulnerability, or a misconfigured cloud service.
What it demonstrates is the potential impact of a compromise when an attacker gains access to a system that holds electronic health records and related patient information.
The Vendor Question
For healthcare organizations, the incident adds another example to a long-standing security problem: sensitive patient information often moves through an ecosystem of technology companies, billing firms, analytics providers, and other business associates.
The HHS breach data show that large incidents can originate both from healthcare providers themselves and from organizations performing services on their behalf.
That makes vendor security part of an organization's broader data-risk picture, even when the underlying application or infrastructure is operated outside the healthcare organization's own network.
The CareCloud breach also shows why the first public description of an incident may be incomplete.
In March, CareCloud knew that one EHR environment had experienced a disruption and that sensitive information might have been affected. By June and July, its investigation and regulatory disclosures had established that there had been a longer period of unauthorized access and confirmed that personal, financial, and medical information had been compromised.
For healthcare organizations relying on cloud-based systems, that progression may be as important as the initial breach itself.
An incident can be contained quickly while the task of determining what happened, whose information was exposed, and how far the effects extend continues for months.
About the Author
John K. Waters is the editor in chief of a number of Converge360.com sites, with a focus on high-end development, AI and future tech. He's been writing about cutting-edge technologies and culture of Silicon Valley for more than two decades, and he's written more than a dozen books. He also co-scripted the documentary film Silicon Valley: A 100 Year Renaissance, which aired on PBS. He can be reached at [email protected].