EHR vendor breach letters reach 345,000 patients after AWS intrusion

State filings show the EHR vendor's AWS-hosted environment breach affected at least 345,000 patients.

MedRisk Staff
By
2 Min Read

CareCloud has started mailing breach notifications to at least 345,000 patients after confirming data was likely exfiltrated from one of its cloud-hosted electronic health record environments.

The Somerset, New Jersey vendor, which provides EHR, revenue cycle management, and practice management software to more than 45,000 providers, suffered a network disruption on March 16, 2026. Investigators determined an unauthorized third party accessed its AWS-hosted environment between March 10 and March 16, and the threat actor claimed to have exfiltrated databases.

State attorney general summaries put the affected population at more than 345,000, including 270,197 Texas residents, though the incident has not yet appeared on the HHS Office for Civil Rights breach portal. Compromised data types include names, addresses, dates of birth, Social Security numbers, driver’s license and government ID numbers, financial account and credit card numbers, and medical and health insurance information. CareCloud is offering 24 months of complimentary identity theft protection.

No ransomware group has claimed responsibility as of August 3, and CareCloud said it has seen no further unauthorized access to the environment since March 16. The incident is the latest in a wave of breaches at hospital software vendors, after Craneware and Change Healthcare disclosed similar attacks, and shows how a compromise at a business associate can ripple across the provider network.

Share This Article