One CareCloud Breach Reaches Thousands of Practices

A breach at a shared health-data platform does not stay inside one clinic. When CareCloud loses a central patient store, the fallout spreads to every downstream practice that relies on it for records and billing, along with the patients whose data sat in that shared system. CareCloud says hackers accessed one electronic health record store for at least six days and that nearly 350,000 people are affected so far. The company serves more than 45,000 providers, and the stolen data included names, addresses, Social Security numbers, government IDs, bank account details, payment card numbers, and medical information. The real burden now moves outward from the vendor. Practices that never saw their own network hit can still inherit patient questions, privacy exposure, and identity-theft fallout because the trust boundary was the shared store, not the individual clinic.

Part of the PlainSec briefing for 2026-07-31

Sources