Skip to main content

Share story

Security

CareCloud discloses unauthorized access to electronic health record environment in SEC filing

CareCloud discloses unauthorized access to electronic health record environment in SEC filing Image: Primary
CareCloud, a Somerset, New Jersey-based healthcare software company, notified the U.S. Securities and Exchange Commission about a security incident that caused network disruption on March 16, 2026. The company is a business associate of hospitals and physician practices and works with more than 45,000 providers. It provides software solutions including electronic health records systems, and one of its six electronic health record environments was subject to unauthorized access. According to the SEC filing, a hacker gained access to the environment for a period of around eight hours, partially disrupting functionality and data access. CareCloud fully restored the environment on the evening of March 16, 2026. The company believes the threat actor no longer has access to its systems. The incident was initially reported to law enforcement. CareCloud notified its cyber insurer and engaged third-party cybersecurity specialists to assist with the investigation and help secure the environment. When it became clear that this was a material incident due to the sensitivity of the data stored within the compromised environment and the potential cost of a data breach, the SEC was notified. CareCloud believes the incident was contained in the one CareCloud Health environment and that no other business systems were involved. The investigation to determine the nature and scope of the unauthorized activity is ongoing, including the extent to which patient data was accessed or exfiltrated and the categories and volume of data involved. As of the date of the SEC filing, the incident has had no material impact on the company's operations. The initial assessment suggests that the incident is not reasonably likely to have a material impact on the company's financial position or results of operations, although the impact of the incident has yet to be fully assessed. There will be costs associated with remediation and response, legal, regulatory, and notification-related matters, and possible effects on patients, customers, counterparties, reputation, and operations. The company holds cyber insurance policies and believes that it has sufficient insurance coverage to cover any costs. CareCloud has not publicly disclosed how any of its clients have been affected, nor has it provided an estimate for the number of individuals whose medical records were exposed in the incident. Notifications will be issued to the affected clients and individuals when they have been identified. At the time of publication, no cyber threat actor is known to have claimed responsibility for the attack.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from HIPAA Journal and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Capital AI
Capital AI

Enveda raises $311 million to advance AI-assisted drug candidates

Enveda has raised $311 million in Series E financing at a $2 billion valuation as it moves drug candidates found through its AI-assisted search of natural compounds into human testing. Catalio Capital Management led the round, wit...

Capital AI
Capital AI

Lightspeed targets $250 million for AI-focused India fund

Lightspeed is seeking $250 million for a new early-stage India fund focused on AI companies, with commitments for 80% of that target already secured, TechCrunch reported from a letter to investors. The proposed fund is half the si...

Science
Science

Infleqtion claims 30 entangled logical qubits on Sqale system

Infleqtion says it created 30 entangled logical qubits on its Sqale quantum computing system, a company-reported step toward operations across error-protected quantum bits. A logical qubit encodes information across multiple physi...

Capital AI
Capital AI

NUS Enterprise launches patent-matching platform and Munich outpost

NUS Enterprise says it has launched Nova, an AI platform developed with Zima Labs to help its staff find commercial partners for university research. It has also established an outpost in Munich through a partnership with Unterneh...

AI Policy
AI Policy

White House asks AI labs to delay model access for UK testers

The White House has asked OpenAI and Anthropic to keep new AI models from the UK's AI Security Institute until the US government tests them, Politico reported. A British official confirmed the reported request to Bloomberg. Politi...

AI Products
AI Products

Microsoft unveils Copilot app with coding and autonomous agents

Microsoft unveiled a redesigned Copilot app that brings chat, coding and autonomous agents into one interface for work. Its Home tab combines chat and task assistance, while Code is designed to create internal apps in a sandbox ho...