CareCloud, Inc.
bd_a0ddde8d6666ff31 · schema v1 · pii pii-v1
Full breach record for CareCloud, Inc. →2 incidents on fileCareCloud, Inc. disclosed a cybersecurity incident affecting its electronic health record environment. An unauthorized third party accessed an AWS environment between March 10 and March 16, 2026, and exfiltrated data including names and potentially government identifiers. CareCloud engaged forensic investigators, secured the environment, and reported to law enforcement. Affected individuals were offered identity theft protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 10, 2026
Begins
Mar 16, 2026
Discovered
Jul 25, 2026
Filed
vs. sector median
+6 wks slower
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- California State AGbd_c48fbacd970b0fb72026-07-25Verified
- HHS OCRbd_3b7e00e7a7706e032026-07-24 · +1dVerified
- Washington State AGbd_ace296eeb27ef3e52026-07-24 · +1dCandidate
- Texas State AGbd_5be63a5d95dd65f12026-07-28 · +3dVerified
Show 5 more filings ↓Show fewer ↑up to 131d gap
- New Hampshire State AGbd_1e42ced8f1d65dd92026-07-31 · +6dVerified
- Oregon State AGbd_42df04e823fae0162026-08-04 · +10dVerified
- South Carolina State AGbd_761c52aedc1f32012026-08-06 · +12dVerified
- SEC 8-Kbd_5d230f4ceefa826c2026-03-27 · +120dVerified by operator
- Pressbd_7b45c93daf45a5c62026-03-16 · +131dVerified by operator
Filing propagation · 10 filings · 8 states
View merged incident ↗Pattern: first filing Mar 16, last Aug 6 (SC) — a 143-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.