Sep 17, 2026
News
3.75 Million Records Exposed: What the CareCloud Breach Means for Your South Florida Practice


A single compromised environment. Eight hours of unauthorized access. 3.75 million patient records.
That's the scope of the data breach disclosed by CareCloud, one of the most widely used cloud-based EHR and practice management platforms in the country, serving more than 45,000 healthcare providers across all 50 states. If your South Florida practice uses CareCloud, or is evaluating it, this incident is worth understanding in detail, because the same gap that let an attacker in could exist in any cloud-hosted system your office depends on.
What actually happened. Here's what's been confirmed so far.
According to CareCloud's own disclosure and its SEC filing, unauthorized access to one of the company's six AWS-hosted EHR environments began around March 10, 2026. The intrusion was discovered on March 16, and the attacker had access for approximately eight hours before the environment was restored. It took until June 24 for CareCloud to confirm that patient data had actually been exposed, and public notifications didn't go out until August 3, nearly five months after the initial breach. The final count, added to the HHS breach portal on August 18, reached 3,756,469 individuals, making it one of the largest healthcare data breaches reported this year.
The exposed data wasn't limited to clinical information. It included names, addresses, dates of birth, Social Security numbers, driver's license and government ID numbers, financial account numbers, credit and debit card numbers, and health insurance information, essentially a complete identity theft kit for millions of patients.
Why the "how" matters more than the headline. CareCloud has not publicly detailed exactly how the attacker got in, beyond confirming it was unauthorized access to one of its AWS-hosted environments. No ransomware group has claimed responsibility, which security researchers note often suggests a ransom was quietly negotiated and paid.
What we do know, from CareCloud's own recommendations to affected organizations, is where the industry's attention needs to go: access controls, authentication processes, and privileged access management. In other words, the cloud infrastructure itself almost certainly wasn't the weak point. The way accounts, credentials, and permissions were managed around it was.
This lines up with what Verizon's 2026 Data Breach Investigations Report found across the healthcare sector as a whole: vulnerability exploitation has now overtaken stolen credentials as the leading way attackers get in, a first in the 19 years Verizon has published the report, and roughly a third of healthcare breaches involve a third-party vendor somewhere in the chain.
What this means if you're a South Florida practice. Most small and mid-sized medical offices in Palm Beach, Broward, and Miami-Dade counties don't run their own servers anymore. Your EHR, your billing system, your patient portal, they all live in someone else's cloud. That's not a bad thing. It's usually more secure than what a five-person office could maintain on its own. But it does mean your HIPAA risk now depends heavily on vendors you don't control.
A few practical takeaways for any practice using CareCloud, or any cloud-based EMR: your Business Associate Agreement is not optional paperwork, since your practice still has HIPAA breach notification obligations if a vendor holding your patients' data has a breach; multi-factor authentication should be non-negotiable on every account that touches patient data, not just admin accounts; ask vendors directly about their access control model and how vendor-side access is logged and reviewed; and don't assume "the cloud is secure" automatically means "our data is secure," since the infrastructure and the access controls around it are two different things.
If your practice received a notification letter, or you're unsure whether your patient population was affected, this is worth a direct conversation with your IT provider, not something to file away. At minimum, confirm your BAA is current, review who in your office has EMR access and whether it's still appropriate, and make sure MFA is enabled everywhere it can be. Breaches like this one aren't a reason to panic. They're a reason to check the basics, because the basics are usually what gets skipped.

