CareCloud warns patient records may have been exposed after brief breach

CareCloud told the SEC that a March 16 network disruption gave a hacker temporary access to one of its six electronic health record environments. That affected EHR was offline for eight hours before being restored. The company decided on March 24 that the incident was material because patient data sensitivity could trigger remediation, legal, notification, and reputational consequences. CareCloud serves over 45,000 providers and is still assessing the extent of any data access or exfiltration.

Part of the PlainSec briefing for 2026-03-31

Sources