DisclosureLens
HackingHealthcareTechnologyHealthcareStolen CredentialsCapture Stored DataData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDHealth (basic)Financial accountHighContained

CareCloud, Inc.

bd_1e42ced8f1d65dd9 · schema v1 · pii pii-v1

Severity

High

Discovered

Mar 16, 2026

Filed

Jul 31, 2026

To disclose

20 weeks

Affected

68,886state residents only

Linked

10 filings

Confidence

66%
Full breach record for CareCloud, Inc.2 incidents on file

CareCloud, Inc. notified the New Hampshire Attorney General on July 31, 2026, of a breach affecting approximately 68,886 NH residents. Between March 10 and March 16, 2026, an unauthorized third party accessed a CareCloud AWS environment and exfiltrated data. Affected data included names, SSNs, DOBs, driver's license numbers, and PHI (health insurance, medications, allergies). Credit card info (including CVV) was affected for a limited subset. CareCloud engaged forensic investigators, reported to law enforcement, and is offering credit monitoring and identity theft protection services.

Incident timeline

undetected · 6 days
discovery → filing · 20 weeks / 137 days

Mar 10, 2026

Begins

Mar 16, 2026

Discovered

Jul 31, 2026

Filed

vs. sector median

+7 wks slower

This filing is one of 10 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (9) · sorted by filing gap

Show 5 more filingsup to 137d gap

Filing propagation · 10 filings · 8 states

View merged incident ↗
PressMar 16 · first
HHS OCR+130d
New Hampshire State AG+137d · this page

Pattern: first filing Mar 16, last Aug 6 (SC) — a 143-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.