- CareCloud confirmed hackers accessed a system that stores patient health records for about eight hours.
- The breach was limited to one environment, and systems were restored the same day.
- The company is still investigating whether any patient data was accessed or stolen.
- Healthcare data remains a top target for cybercriminals due to its long-term value.
Healthcare data breaches keep coming. Now, CareCloud is the latest to confirm a serious security incident.
The company says hackers accessed one of its systems that stores electronic health records, not confirmed patient records themselves. The intrusion lasted more than eight hours on March 16. That window matters because even a short breach can expose sensitive data at scale.
At this point, there is still uncertainty. CareCloud has not confirmed whether any data was taken or what specific information may be involved. However, the investigation is ongoing, and the company has brought in outside cybersecurity experts.

What exactly happened inside CareCloud’s systems
CareCloud operates multiple environments where patient records are stored. According to its filing with the U.S. Securities and Exchange Commission, attackers gained access to one of those environments.
Here is what we know so far:
- Unauthorized access began on March 16
- Hackers stayed inside for more than eight hours
- The company restored full system functionality and data access the same day
- The company believes the attackers are no longer inside
CareCloud also says the incident was contained to that single environment and did not impact its other systems or platforms. Even so, the biggest unanswered question remains whether any data left the system. That detail matters because stolen health data often fuels identity theft, insurance fraud and targeted scams.
Why healthcare data is such a valuable target
Healthcare companies sit on a goldmine of personal information. That includes names, Social Security numbers and medical histories. Unlike a credit card, you cannot simply cancel your medical history. We saw the scale of this risk during the Change Healthcare ransomware attack. That breach disrupted systems across the U.S. and delayed care for weeks. It also exposed just how interconnected the healthcare infrastructure has become. CareCloud serves more than 45,000 providers and supports millions of patients. That kind of reach makes any incident more serious.

Where patient data may be stored
CareCloud has not shared full technical details yet. Public records suggest much of its infrastructure relies on Amazon Web Services. Cloud platforms are widely used across healthcare. They offer scale and flexibility. At the same time, they require strict security controls to prevent unauthorized access. It is still unclear how CareCloud separates or backs up data across its systems. That detail could affect how far attackers were able to move once inside. We reached out to CareCloud for a comment, but did not hear back before our deadline.
What this means to you
Even if you have never heard of CareCloud, your doctor might use it. That is how these breaches work. A behind-the-scenes company gets compromised, and patients feel the impact later. Right now, there is no confirmation that patient data was stolen. Still, this is the moment to stay alert. If your information was involved, notifications could come weeks or even months later.

Watch the latest episode of The CyberGuy Report.
Missed this event? Sign up via the registration form and see our live recording.
See Kurt’s latest Amazon picks for useful gadgets, smart home upgrades and everyday tech worth grabbing while the deals last.
Ways to stay safe from healthcare data breaches
Healthcare breaches can feel out of your control. Still, a few simple habits can make a real difference.
1) Watch your medical statements closely
Check every explanation of benefits and billing statement you receive. Look for charges, prescriptions or visits you do not recognize. Even a small, unfamiliar charge can signal fraud. If something looks off, contact your insurer or provider right away.
2) Set up identity theft monitoring
Health data can be used to open accounts, file fake claims or commit identity theft. Identity Theft companies such as Aura can monitor personal information like your Social Security Number (SSN), phone number, and email address, and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals. The faster you catch it, the easier it is to limit the damage.
Exclusive CyberGuy deal: Save up to 68% today: Get Aura’s award-winning identity theft protection and credit monitoring for as low as $9/month when billed annually.
3) Consider data removal services
Your personal details often end up on data broker sites without your knowledge. That information can be used to target you after a breach. Removing your data from these sites with a data removal service like Incogni reduces how much scammers can find and use against you.
Incogni, a service I trust 100% and use myself, helps automate the process by submitting removal requests to hundreds of data brokers and people-search sites on your behalf.
Incogni automatically contacts data brokers on your behalf and requests the removal of your personal information. It also continues monitoring those sites and submits new removal requests if your data reappears.
- Incogni currently removes personal data from 420+ data broker and people-search websites, and its Unlimited plan allows you to request removals from as many additional sites as you need.
- Incogni has also received third-party assurance from Deloitte, validating its marketing claims.
- The goal is simple: make it much harder for strangers, scammers, and cybercriminals to find your personal information online.
CyberGuy readers get 60% off Incogni’s annual plans using the links in this article.
The service also includes a 30-day money-back guarantee, so you can try it risk-free and see how much of your information is exposed online.
Is your personal information exposed online?
Run a free scan to see if your personal info is compromised. Results arrive by email in about an hour.
4) Use strong antivirus protection
If you receive emails about medical updates or billing issues, be extra careful. Malicious links and attachments are common after breaches. Strong antivirus software such as Norton Antivirus Plus (CyberGuy Deal: 58% off) can help detect threats before you click and stop harmful downloads in real time.
5) Use strong, unique passwords
Secure your patient portals with a password you do not use anywhere else. Reusing passwords makes it easier for attackers to access multiple accounts. A password manager such as NordPass can generate and store strong passwords for you so you do not have to remember them. CyberGuy Exclusive: Save 52% now with CyberGuy’s exclusive NordPass offer – Get 1 extra month FREE with a 2-year plan. Try 30 days risk-free for only $1.43 per month! (our review here)
6) Enable two-factor authentication
Turn on two-factor authentication (2FA) if your provider offers it. This adds a second step, such as a code sent to your phone. Even if someone gets your password, this extra layer can stop them from getting into your account.
7) Be cautious with follow-up scams
After a breach, scammers often pose as healthcare providers or support teams. They may send emails, texts or even call you. Do not click links or share personal details unless you verify the source. When in doubt, go directly to your provider’s official website or call their listed number.
Related Links:
- 1 billion identity records exposed in ID verification data leak
- Millions of AI chat messages exposed in app data leak
- Banking tech data breach exposes 672K in ransomware attack
Kurt’s key takeaways
The CareCloud data breach is still unfolding. That uncertainty is part of the problem. Healthcare systems are complex. They rely on multiple vendors, cloud services and interconnected tools. That creates more entry points for attackers. Even when companies respond quickly, the ripple effects can last much longer.
If your most sensitive health data can pass through multiple companies you have never heard of, who should be responsible for keeping it safe? Let us know in the comments below.
FOR MORE OF MY TECH TIPS & SECURITY ALERTS, SUBSCRIBE TO MY FREE CYBERGUY REPORT NEWSLETTER HERE
Copyright 2026 CyberGuy.com. All rights reserved. CyberGuy.com articles and content may contain affiliate links that earn a commission when purchases are made.
