ALITEQ.

a healthcare company sat on your stolen medical records for months before telling you

CareCloud confirmed in June that hackers had walked off with your Social Security number and diagnosis history. It didn't start mailing letters until August 3.

Priya NairUpdated 1h ago7 min readWeb story
Digital patient records displayed on a healthcare computer system

CareCloud started mailing breach notification letters on August 3, 2026, telling at least 345,000 people — first reported by HIPAA Journal — that hackers had already been inside its systems for months. The company detected an intrusion in one of its electronic health record environments on March 16. It confirmed patient data had actually been stolen on June 24. It waited another six weeks after that before telling anyone.

The timeline that should worry you

How a March breach became an August letter

  1. March 10, 2026

    Attackers gain access to one of CareCloud's six AWS-hosted electronic health record environments.

  2. March 16, 2026

    CareCloud detects the intrusion after a network disruption knocks out access for about eight hours, and restores the environment that evening.

  3. June 24, 2026

    A forensic investigation confirms the attacker actually removed files containing patient data — not just accessed the environment.

  4. August 3, 2026

    CareCloud begins mailing notification letters to at least 345,000 affected patients.

HIPAA generally requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach. CareCloud's own timeline puts detection at March 16 and the first letters going out roughly 140 days later. As TechCrunch reported when notifications began, CareCloud hasn't detailed why the additional six weeks passed between confirming the theft in June and mailing letters in August. My read: that gap is the part that deserves scrutiny, not the initial three months of forensic work, which is normal for a complex intrusion. Six weeks between 'we know for certain your Social Security number is gone' and 'we told you' is a business decision, not a technical one.

Electronic health record system displayed on a computer screen
The breach hit one of CareCloud's six AWS-hosted EHR environments — the other five were unaffected. · Unsplash

What was actually taken

According to Security Affairs' review of the breach notice, the exposed data spans both identity and clinical records:

  • Full name, home address, date of birth
  • Social Security number
  • Driver's license or other government ID number
  • Bank account details, payment card numbers, expiration dates and security codes
  • Medical record numbers, diagnoses, treatment details, prescriptions and lab results
  • Health insurance and billing/claims information

What to actually do if you got the letter

Enroll in the identity theft protection CareCloud is offering — up to 24 months, where state law requires it.

Place a credit freeze with all three bureaus, not just a fraud alert — a freeze blocks new accounts outright.

Request an Explanation of Benefits audit from your insurer and watch for claims you don't recognize.

Treat any unexpected medical bill or collections notice over the next year as a reason to check your records for entries that aren't yours.

345,000+

People notified

including 270,197 Texas residents

1 of 6

EHR environments hit

AWS-hosted

~140 days

Detection to notice

March 16 to August 3

Why healthcare breaches keep landing like this

This isn't an isolated case of a slow-moving vendor. Healthcare data keeps getting stolen in bulk because it sits in exactly the kind of sprawling, multi-environment cloud infrastructure CareCloud describes — six separate EHR environments, only one of which failed — and because medical records resell for more than a credit card number precisely because they don't expire. I'd rather see companies over-communicate during a forensic investigation, even with incomplete information, than deliver one polished letter five months late. 'We don't know yet, but here's what we're checking' beats silence.

Was my payment card information exposed even if I never paid CareCloud directly?
Possibly, if your healthcare provider used CareCloud's billing systems. Financial account numbers and payment card details are explicitly listed among the compromised data types, alongside medical and insurance information.
Why did it take from March to August to notify anyone?
CareCloud detected the intrusion March 16 but says it took until June 24 to confirm through forensic investigation that files were actually removed, not just accessed. Notification letters then began August 3 — a gap the company hasn't publicly explained in detail.
Would I recognize the CareCloud name as a patient?
Probably not. CareCloud provides electronic health record and billing infrastructure to healthcare providers — most patients would only have interacted with their doctor's office or clinic, which is part of why breach letters like this one catch people off guard.
What's the difference between a fraud alert and a credit freeze?
A fraud alert asks lenders to verify your identity before opening new credit. A freeze blocks new accounts from being opened at all until you lift it. For a breach involving a full Social Security number, a freeze is the stronger protection.

CareCloud joins a run of breaches this year — Allstate's ransomware claim, the MCBS medical billing breach, and Coca-Cola's Fairlife breach all landed in the same stretch of 2026. If there's a pattern, it's this: the initial intrusion is rarely the whole story anymore. How long a company takes to tell you, and how much of the timeline it's willing to show, is becoming its own signal of how seriously to take the rest of the letter.

Software & Systems Editor

Priya Nair

Priya has daily-driven more Linux distros than she can name and treats her setup like a workshop. She covers the operating systems, apps and settings worth your time — and cheerfully calls out the 'optimizations' that just quietly break your machine.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading