Wall Street Learned About the CareCloud Hack in March. Patients Got Their Letters in July — 345,000 Affected and Counting
A medical-records company told the SEC about its breach within days. The people whose Social Security numbers, medication lists — and in some cases card security codes — were taken waited four months for a letter. There is no settlement to claim, two lawsuits are pending, and one deadline is real: free identity protection ends December 17.
By Settlement Insight Data Desk ·
Four months from intrusion to mailbox
CareCloud is not a household name, but if your doctor's office runs its billing or its talkEHR records platform, your file may live on CareCloud's servers. Per the company's SEC filing, an unauthorized actor was inside part of its Amazon-hosted environment from March 10 to March 16, 2026 — six days — before an eight-hour service disruption on March 16 gave the intrusion away. The company determined the incident was material on March 24 and filed its Form 8-K under Item 1.05 on March 27. One of its six electronic-health-record environments was affected.
Investors, in other words, were formally told within about two weeks. Patients were not: notification letters did not start going out until about July 25, 2026, per CareCloud's submission to California's attorney general — roughly four months after the intrusion. That gap is legal (HIPAA allows 60 days from 'discovery,' and forensic reviews of what exactly was taken routinely stretch timelines), but it matters practically: whatever a criminal planned to do with your data, they had a four-month head start.
What was in the files — including, for some, the card security code
According to the notification letter filed with California's attorney general, as reported by the security trade press, the exposed data varies by person and can include: name, address, date of birth, Social Security number, driver's license or passport number, health-insurance details (member and policy numbers, provider names, medications, allergies), bank-account information, and credit or debit card numbers — for a limited group, complete card details including the CVV security code. That last item is unusual and worth acting on: monitoring does not stop a card with a live CVV; replacing the card does.
How many people? There is no single official total. The figure circulating — at least 345,000, with some outlets now saying over 350,000 — is an aggregation of CareCloud's separate filings with state regulators: 270,197 in Texas and 72,102 in Massachusetts alone, with Maine, New Hampshire and other states also notified. The count has grown with each new filing, and as of early August the trade press notes the incident had not yet appeared on the federal HHS breach portal — so the ceiling is probably not in yet.
Two lawsuits, zero settlements — ignore the claim-form ads
At least two federal class actions are pending: Arslanian v. CareCloud, No. 1:26-cv-23048 in the Southern District of Florida, and Applefield v. CareCloud, No. 3:26-cv-03772 in the District of New Jersey, filed April 9. We could not verify any consolidation order as of publication. More importantly for your wallet: there is no settlement, no claims portal, and no payout to apply for. Law-firm 'investigation' pages collecting sign-ups are marketing for a case that may eventually pay something — they are not a claim form.
The aggregator sloppiness is already measurable. One claims-tracking site currently headlines the incident as '72k Patients Impacted' — that is the Massachusetts number alone, off by a factor of five. Earlier coverage elsewhere confused the breach date with June 4, which is actually the date of CareCloud's annual shareholder meeting. When the details differ, the SEC filing and the state-AG notices win.
The one deadline that is real: December 17
What CareCloud is offering affected patients is free identity protection through IDX: credit and dark-web (CyberScan) monitoring, a $1 million identity-theft reimbursement policy, and full-service restoration if something happens. Enrollment requires the code from your letter and closes on December 17, 2026 — call (866) 329-9984 to enroll; general questions go to the incident line at (800) 411-9670 (weekdays, 9 a.m.–5 p.m. ET).
Beyond that, the standard playbook applies with extra urgency because Social Security numbers are involved: freeze your credit at all three bureaus (free, takes minutes), and if your letter mentions payment-card data, ask your bank for a new card rather than waiting for fraud alerts. If a settlement with a real claims process emerges from the litigation, it will be announced in court filings — we track this case and will report when there is actually something to file.
The Data Behind This Story
- People affected (aggregated state filings)
- 345,000+ and climbing
- Texas residents
- 270,197
- Massachusetts residents
- 72,102
- Intrusion window
- March 10–16, 2026
- First notice letters
- ≈ July 25, 2026
- Free IDX enrollment deadline
- December 17, 2026
- Settlement to claim
- None yet
- Source: CareCloud Form 8-K (Item 1.05), filed with the SEC March 27, 2026 — accession 0001493152-26-013239
- Source: California AG data-breach submission SB24-627090 (notice letters beginning ≈ July 25, 2026); notice details as reported by trade press citing the filed letter
- Source: State-AG counts: Texas 270,197; Massachusetts 72,102 — aggregated by HIPAA Journal, TechCrunch (July 30, 2026), SecurityWeek and DataBreaches.net (Aug 1, 2026)
- Source: Court dockets: Arslanian v. CareCloud, No. 1:26-cv-23048 (S.D. Fla.); Applefield v. CareCloud, No. 3:26-cv-03772 (D.N.J.)
- Source: IDX enrollment (866) 329-9984, deadline Dec 17, 2026; incident line (800) 411-9670
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.