FEDERALItem 1.05 · mandatoryHackingHealthcareTechnologyHealthcareSoftwareCustomer Data InvolvedPHILowContained
CareCloud, Inc.
bd_5d230f4ceefa826c · schema v1 · pii pii-v1
Full breach record for CareCloud, Inc. →On March 16, 2026, CareCloud, Inc. experienced a temporary network disruption in its CareCloud Health division affecting 1 of 6 electronic health record environments for approximately 8 hours. The company believes an unauthorized third party temporarily had access. Functionality was restored the same evening and the incident was contained on the day of discovery. CareCloud is investigating whether patient information was accessed or exfiltrated; on March 24, 2026 it determined the incident material under Item 1.05.
SEC clockMateriality determined Mar 24, 2026 → Filed Mar 27, 20263d ✓ SEC 4-day OK11 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1582982/000149315226013239/form8-k.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 27, 2026
- Raw hash
- e829c1fba01b997b4c5714b2ca92a56be2aa8b7ca67fdfb07c49ba5dbff9970e
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- CareCloud, Inc.norm: carecloud
- SEC CIK
- 0001582982
- Domain
- carecloud.com
Victim entity
- Name
- CareCloud, Inc.norm: carecloud
- SEC CIK
- 0001582982
- Domain
- carecloud.com
- Industry
- Healthcare IT / Electronic Health Records
- Industry
- HealthcarellmTechnologyllmNAICS 513210 · Software Publishers
Incident
- Discovered
- Mar 16, 2026
- Materiality determined
- Mar 24, 2026
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported the matter to the appropriate law enforcement authorities
Compliance
- Time to disclose
- 11 days(11 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 3d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Mar 24, 2026→ Filed: Mar 27, 20263d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.