HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPHIIDENTITY_BASICHEALTH_BASICLowContained
CareCloud, Inc.
bd_c48fbacd970b0fb7 · schema v1 · pii pii-v1
Full breach record for CareCloud, Inc. →CareCloud, Inc. disclosed that an unauthorized third party accessed its AWS environment between March 10 and March 16, 2026, and claimed to have exfiltrated data. The incident involved protected health information (PHI) and personal information including names. CareCloud engaged forensic experts, secured the environment, and confirmed no persistent access remains. Identity theft protection services are being offered to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_5be63a5d95dd65f1Texas State AGfiled 2026-07-28(3d gap)Verified
- bd_a0ddde8d6666ff31Massachusetts State AGfiled 2026-07-01(24d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-627090
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 25, 2026
- Raw hash
- f9dd1ac93e8f874484cde09ef955e45b6beb13035f8de6d0d0bd4577fc381d68
Reporting entity
- Name
- CareCloud, Inc.norm: carecloud
- Domain
- carecloud.com
Victim entity
- Name
- CareCloud, Inc.norm: carecloud
- Domain
- carecloud.com
Incident
- Discovered
- Mar 16, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 19 weeks(131 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.