CareCloud notifies 3.8 million after March AWS cloud environment hack
This digest was compiled by AI from multiple sources — links to the originals are below.

CareCloud is notifying nearly 3.8 million individuals after a March hacking incident involving one of its Amazon Web Services cloud environments, the company said. The company listed names, addresses, Social Security numbers, financial account numbers, and medical and health insurance information among the data at risk, and several law firms are investigating potential class action litigation. The incident ranks as the third-largest health data breach reported to the U.S. Department of Health and Human Services in 2026, even as no threat actor group has claimed responsibility.
Key Facts
- CareCloud is notifying nearly 3.8 million individuals after a March breach of one of its AWS cloud environments.
- The data listed as potentially affected includes names, addresses, dates of birth, Social Security numbers, driver's license numbers, financial account numbers, credit and debit card numbers, and medical and health insurance information.
- As of Wednesday, the incident ranked as the third-largest health data breach posted to the HHS HIPAA Breach Reporting Tool website in 2026.
- No threat actor group has taken responsibility for the hack as of Wednesday.
Breach Timeline
CareCloud first reported the incident to the U.S. Securities and Exchange Commission in March. On March 16, the company experienced a network disruption that affected one of its electronic health record environments. An investigation determined that between March 10 and March 16 a threat actor accessed one of the company's AWS environments and claimed to have exfiltrated data from databases within it. As of March 16, CareCloud said there was no evidence of unauthorized activity within its environment.
Exposed Information
The company listed patient names, addresses, dates of birth, Social Security numbers, and driver's license numbers among the potentially affected information. Government ID numbers, financial account numbers, credit and debit card numbers, and medical and health insurance information were also listed. CareCloud said it is continuing to strengthen the security of its systems but did not provide details. Several national law firms have issued public statements saying they are investigating the hack for potential class action litigation.
Breach Scale
As of Wednesday, the CareCloud hack ranked as the third-largest health data breach posted so far in 2026 on the HHS HIPAA Breach Reporting Tool website. CareCloud is one of 166 other major health data breaches reported by third-party vendors to HHS so far this year, affecting nearly 21.4 million people. In total, the HHS website listed 425 major protected health information breaches that affected nearly 51.4 million people in 2026.
1 source
CareCloud notifies 3.8 million after March AWS cloud environment hack



