CareCloud Data Breach — March 2026 Patient Record Incident
An unauthorized party reached one of CareCloud's electronic health record environments in March 2026. Law firms are investigating; as of August 2026 no class action has been filed and no settlement exists.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened
CareCloud, a healthcare technology company based in Somerset, New Jersey, disclosed that an unauthorized third party accessed one of its electronic health record environments in March 2026. Public reporting places the access in the window of March 10–16, 2026; CareCloud filed a Form 8-K announcing the incident on March 24, 2026.
The company's investigation confirmed that protected health information and other sensitive patient data may have been accessed. Public reporting puts the number of affected patients at roughly 411,000. Because CareCloud provides billing and records software to medical practices, affected people are patients of CareCloud's client practices rather than CareCloud's own customers — which is why many notice recipients have never heard the company's name.
Case Details
No class action complaint identified as of August 2026. Multiple plaintiffs' firms have announced investigations; CareCloud disclosed the incident via Form 8-K on March 24, 2026.
Current Status
Who Is Affected
Patients whose records sat in the affected environment — in practice, patients of medical practices that use CareCloud's electronic health record and billing platform. The clearest confirmation is a breach notification letter naming CareCloud or your provider's records vendor.
Because the data involved is protected health information, exposure can include far more sensitive material than a typical retail breach: diagnoses, treatment details, insurance and billing information. That is also why plaintiffs' firms are watching this case closely.
What This Could Be Worth — Honestly
Timeline
- 1
March 10–16, 2026 — Unauthorized access
An unauthorized third party reaches one of CareCloud's electronic health record environments containing sensitive patient information.
- 2
March 24, 2026 — Public disclosure
CareCloud files a Form 8-K with the SEC announcing the cybersecurity incident.
- 3
April 2026 — Law firm investigations open
Data-breach firms including Barnow and Associates announce investigations and begin speaking with patients who received notices.
- 4
2026 — Notifications to affected patients
CareCloud begins notifying affected individuals. A notice letter is the clearest confirmation that your records were involved.
- 5
Next — Filing or nothing
Either a class action is filed and the case proceeds, or the investigations close without a complaint. We update this page when the status changes rather than implying a case exists.
Scam Warnings
Health-data breaches draw fraud aimed at patients, who are often anxious and unfamiliar with the vendor's name.
"Claim your CareCloud settlement"
There is no settlement and no claim form. Any page offering one for CareCloud is fabricating it.
Callers claiming to be your doctor's billing office
Exposed billing data makes convincing pretexts possible. Hang up and call your provider back on the number from your own records — never one supplied by the caller.
"Verify your identity to protect your medical records"
No legitimate party asks for your full Social Security number, insurance login or banking details by email or phone in response to a breach.
Frequently Asked Questions
Is there a CareCloud settlement I can claim?
No. As of August 2026 no class action has even been filed against CareCloud over this incident — only law firm investigations exist. That means no fund, no administrator and no claim form. Be sceptical of any site that suggests otherwise.
I've never heard of CareCloud — why did I get a notice?
CareCloud provides electronic health record and billing software to medical practices. If your doctor's office uses it, your records may have been stored in the affected environment even though you never dealt with CareCloud directly.
What kind of information was involved?
CareCloud confirmed that protected health information and other sensitive patient data may have been accessed. Health records typically contain far more than a name and email — diagnoses, treatment history, insurance and billing details — which is why these breaches are treated more seriously than retail incidents.
What should I do now?
Keep your notice letter, enrol in any monitoring offered, review your explanation-of-benefits statements for care you did not receive (a sign of medical identity theft), and check your credit report. If a case is later filed and settles, class members are normally contacted directly — you do not need to register anywhere in advance.
Will there be a lawsuit?
Possibly, but it is not guaranteed. Several firms are investigating, which often precedes a filing — but investigations also close without one. We would rather say that plainly than imply a case exists.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.