Electronic health record vendor CareCloud has confirmed that a March intrusion into one of its AWS-hosted environments compromised data belonging to roughly 3.7 million people, one of the larger healthcare breaches disclosed this year and a reminder that the health sector’s move to cloud-hosted EHR platforms has not come with a matching upgrade in breach containment speed.
According to a notification CareCloud filed with the California Attorney General’s office, an unauthorized third party had access to the affected environment beginning March 10, 2026, with the company detecting and containing the intrusion around March 16. A CareCloud filing with the SEC the same month described an “unauthorized third party who temporarily had access to the system.” The compromised data spans Social Security numbers, government ID numbers, payment card details, and medical and insurance records.
What stands out is the gap between containment and disclosure. CareCloud restored system functionality within about eight hours in mid-March, but did not begin notifying affected individuals until late July, and the fuller scope, 3.7 million people rather than the roughly 350,000 first reported, only became public in mid-August. That five-month span between a contained incident and a completed public accounting is not unusual for healthcare breaches, but it is exactly the kind of lag that turns a technical containment win into a trust problem, since patients and providers had no way to act on exposure they did not yet know about.
For security leaders at healthcare and health-tech vendors, the original insight here is not the AWS environment itself, it is the scoping process. CareCloud’s own numbers grew nearly tenfold between its first disclosed estimate and its final one, which points to a review process built to satisfy minimum notification timelines rather than to compress the interval between detection and an accurate public count. Vendors handling patient data should treat breach scoping speed, not just detection speed, as a metric worth measuring against peers like the smaller, faster-disclosed breaches that increasingly set the comparison bar.
Source: California Attorney General, Data Breach Notification Report