CareCloud Reports Unauthorized Access to Electronic Health Record System on March 16
CareCloud disclosed that unauthorized actors accessed one of its electronic health record environments for approximately eight hours on March 16. The company stated the incident was contained to a single environment and did not affect other systems. An investigation is underway with external cybersecurity experts to determine if any data was exposed.
Substrate placeholder — needs reviewCareCloud, a healthcare technology company, reported an unauthorized access incident involving one of its electronic health record environments. The breach occurred on March 16 and lasted about eight hours. The company has not confirmed whether any patient data was accessed or exfiltrated.
U.S. Securities and Exchange Commission, attackers gained entry to this specific environment. CareCloud operates multiple such environments for storing patient records. The incident was isolated and did not impact other systems or platforms.
engaged outside cybersecurity experts to assist with the investigation.
The company has not provided details on the specific information potentially involved. As of the latest update, investigators are reviewing the possible exposure of data. Public records indicate that CareCloud's infrastructure relies in part on Amazon Web Services, a cloud platform commonly used in healthcare for scalability.
However, technical details on data separation or backups across systems remain undisclosed. CareCloud did not respond to requests for additional comment before the reporting deadline.
serves more than 45,000 providers and supports millions of patients across the United States.
Healthcare systems hold sensitive information such as names, Social Security numbers, and medical histories. Previous incidents, such as the Change Healthcare ransomware attack, have disrupted services nationwide and highlighted vulnerabilities in interconnected healthcare infrastructure. The stakes involve potential risks to patient privacy and operational continuity.
If data exposure is confirmed, affected individuals may receive notifications in the coming weeks or months. Regulatory requirements mandate reporting significant breaches to authorities and impacted parties.
The ongoing investigation will determine the full scope of the incident.
CareCloud has contained the access, reducing immediate threats to other environments. Patients whose providers use CareCloud services may monitor their medical statements for unrecognized activity and consider identity monitoring options. Broader implications include heightened scrutiny on cloud-based healthcare security.
Industry experts emphasize the need for robust controls to protect against unauthorized access. Updates from CareCloud are expected as the review progresses.
Key Facts
Story Timeline
3 events- March 16, 2024
Unauthorized actors accessed one CareCloud electronic health record environment for about eight hours.
1 sourceFox News - Post-March 16, 2024
CareCloud contained the incident to a single environment and engaged external cybersecurity experts for investigation.
1 sourceFox News - Recent filing
CareCloud disclosed the incident in a U.S. Securities and Exchange Commission filing.
1 sourceFox News
Potential Impact
- 01
Individuals might monitor statements for potential fraud related to health data.
- 02
Patients may receive delayed notifications if data exposure is confirmed.
- 03
Healthcare providers using CareCloud could face operational reviews.
- 04
Increased regulatory scrutiny on cloud security in healthcare may follow.
Transparency Panel
Related Stories
EuronewsWorld Urban Forum 2026 Draws 57,000 Participants from 176 Countries
The 13th World Urban Forum concluded with discussions on housing, climate resilience and urban governance. Organisers reported that the sessions informed future strategic priorities.
theverge.comTrump Mobile website still lists T1 phone as American-made
The product page for the T1 phone continues to describe the device as American-made. The Verge reported that the site may conflict with FTC advertising rules. The phone was announced in June 2025.
France 24EU Discusses Readiness for Artificial Intelligence Changes
A France 24 program examined whether European Union policies can address the effects of artificial intelligence. The discussion covered potential impacts across daily life and economic sectors.