Learn More about Benny Czarny's Book Cybersecurity Upside Down

Learn More
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

A Six-Day Intrusion Exposed 3.75 Million Patient Records at CareCloud

CareCloud has confirmed a March 2026 attack on one of its EHR environments.
By Joseph Nguyen, Product Marketing Manager
Share this Post

CareCloud, a healthcare software vendor based in Somerset, New Jersey, has confirmed a March 2026 attack on one of its EHR (Electronic Health Record) environments. The attack affected over 3.7 million people. The HHS (Health and Human Services) Office for Civil Rights breach portal now lists it among the largest healthcare breaches of the year. That ranking comes from The HIPAA Journal (August 2026). Forensic investigators placed the unauthorized access in a window of roughly six days, and the attacker claimed to have exfiltrated databases in that time.

Just six days of access produced millions of complete patient identities.

That gap between dwell time and damage is the part worth studying. Access controls decide how long an intruder stays. The contents of the files they reach decide how much that visit is worth, and that is the variable Proactive DLP™ is built to change before an attacker ever gets that far.

What the Attacker Reached

CareCloud has confirmed the categories of data involved, and the combination matters more than any single field. Affected records included some mix of the following:

  • Names and home addresses
  • Dates of birth
  • Social Security numbers
  • Driver's license and other government-issued identification numbers
  • Financial account numbers
  • Credit and debit card numbers
  • Medical information and health insurance details

A stolen card number expires. A date of birth paired with a Social Security number and a diagnosis does not. Each record in this breach carried enough to open credit and file fraudulent claims. It also carried enough to build a convincing pretext for the next attack against the patient or their provider.

None of that value depends on an intruder recognizing what they found: a policy that hashes or redacts those fields before the file reaches storage removes the value regardless of who eventually reads it.

The Vendor Layer Concentrates the Damage

CareCloud operates as a business associate under HIPAA and works with more than 45,000 providers. That’s how a single compromised environment reached patients across thousands of covered entities, none of whom controlled the environment in question.

The HHS for Civil Rights breach portal now lists CareCloud Breach among the largest healthcare breaches in 2026

Every one of those providers still owes its patients a breach notification and still carries the reputational cost. Vendor concentration turns one intrusion into a shared liability, which is why data handled on behalf of a covered entity deserves the same scrutiny as data held inside it. IBM's 2026 Report puts the average healthcare breach at $6.64 million, the highest of any industry for the thirteenth consecutive year, with the United States averaging $11.5 million across all sectors. Neither figure accounts for how one incident propagates across a provider network.

Where Sensitive Patient Data Actually Sits

Discussion of healthcare breaches tends to focus on database records. In practice, PHI (Protected Health Information) accumulates in files. Examples include scanned intake forms, insurance cards photographed and attached as PDFs, claims documentation, exported spreadsheets, DICOM (Digital Imaging and Communications in Medicine) studies, and email attachments moving between a practice and its billing vendor.

Those files are harder to inventory than a database column, and they hide data in places a text search never reaches:

  • Scanned and photographed documents, where identifiers exist only as pixels
  • Cropped images inside Microsoft Office files, which retain the region the author believed they deleted
  • Invisible or very small text, used to conceal data from a reviewer
  • DICOM headers and burned-in annotations, which carry patient, physician, and institution details alongside the image
  • File metadata such as author, GPS coordinates, and revision history

Every copy of a file that keeps its identifiers in readable form is another record available to anyone who reaches the storage it sits in.

Proactive DLP™ Limits What a Breach Can Expose

Proactive DLP™ Technology inspects file content at the points where files move, then applies a policy action based on what it finds. It covers 125+ file types and inspects recursively, so archives, embedded objects, and nested layers are examined rather than skipped.

Detection maps closely to the categories CareCloud reported. Built-in and AI-based detectors cover Social Security numbers, credit card numbers, driver's license numbers, national identification numbers, passport numbers, and dates of birth. Coverage extends to personal names, phone numbers, common medical conditions, blood type, national drug codes, and custom patterns defined by regular expression. OCR extends that coverage to non-searchable PDFs and image files. A scanned insurance form is read the same way a text document is.

Example of DICOM anonymization by Proactive DLP™
Example of Social Security Number redacted by Proactive DLP™

Once content is identified, policy decides what happens to it:

  • Redaction and substitution conceal identifiers while preserving document structure and readability, across formats including PDF, Word, Excel, PowerPoint, CSV, and OCR-processed images
  • Hashing replaces an identifier with a non-reversible value using SHA-256, SHA-384, or SHA-512, which lets analytics and third-party sharing continue without moving live identifiers
  • DICOM anonymization strips patient, exam, and physician data from the header and optionally removes burned-in annotations, with a default configuration built around the HIPAA Safe Harbor provision
  • Metadata removal clears author, GPS, and version fields from images, Office files, and PDFs
  • Cropped-area removal permanently deletes hidden image regions in Microsoft Office files
  • Tagging and classification embed the detection result in the file itself, giving a SIEM (Security Information and Event Management) or document management system something to act on
  • Blocking stops a file outright when policy does not permit the content to move

Proactive DLP™ Technology runs inside MetaDefender Core™, MetaDefender ICAP Server, MetaDefender Email Security, MetaDefender Kiosk, and MetaDefender Managed File Transfer. Together, they place enforcement at web uploads, email, removable media, and file transfer workflows.

The Variable You Can Still Control

An intrusion timeline is set by the attacker. The readability of the data waiting at the end of it is set by policy, and it is set before the attack begins. A patient record with its Social Security number hashed and its scanned attachments redacted is a materially smaller loss than the same record stored intact.

For healthcare organizations and the vendors serving them, that means treating de-identification as an ingestion and transfer control rather than a reporting-time cleanup. Decide what identifiers each system genuinely needs, then enforce that decision on every file entering it. Teams looking to close that gap can start by seeing how Proactive DLP™ Technology applies redaction, hashing, and anonymization before data ever leaves storage.

Stay Up-to-Date With OPSWAT!

Sign up today to receive the latest company updates, stories, event info, and more.