CareCloud's breach reached 3.75 million people and took 131 days to reach them. The rule it was measured against sets 60 days twice
The HIPAA deadline everyone quotes is two consecutive 60-day windows, both starting at a word the regulated party defines in retrospect. And the letter filed with California leaves the field describing what was taken as an unfilled merge placeholder.
By Parminder Kumar Sharma · · 6 min read

What the notification letter actually says
CareCloud disclosed on 20 August 2026 that a breach first reported to the Securities and Exchange Commission in March affected 3,756,469 individuals. The company is a healthcare technology provider, publicly traded, supplying electronic health records, billing and revenue-cycle services to healthcare organisations.
The document worth reading is not the coverage. It is the notification letter CareCloud filed with the California Attorney General, which is public, and which sets out its own timeline in its own words.
On March 16, 2026, CareCloud experienced a network disruption in its CareCloud Health division that impacted one of its electronic health record environments.
The investigation determined that, between March 10 and March 16, 2026, an unauthorized third party accessed one of CareCloud's [environments].
On June 24, 2026, CareCloud determined that the affected data may have included your full name and one (1) or more of the following.
Three dates, from the company: discovery on 16 March, a determination of what was taken on 24 June, and letters from 25 July. That is 131 days from the disruption to the first letter.
The rule sets sixty days, and sets it twice
Two statutory windows, and the time that actually passed
The HIPAA Breach Notification Rule sets the same deadline in two places, because a company like CareCloud is usually a business associate rather than the entity holding the patient relationship.
The two clocks, quoted
| Section | Who tells whom | The deadline |
|---|---|---|
| 164.410(b) | Business associate tells the covered entity | Without unreasonable delay and in no case later than 60 calendar days after discovery of a breach |
| 164.404(b) | Covered entity tells the individual | Without unreasonable delay and in no case later than 60 calendar days after discovery of a breach |
| 164.410(a)(2) | Both, on when the clock starts | The first day on which such breach is known, or by exercising reasonable diligence would have been known |
Run those consecutively and 120 days is available before anybody has done anything unusual. That accounts for most of the gap, and it is why the honest version of this story is not that CareCloud broke the rule. It is that the deadline is anchored to a word.
Discovery is defined by knowledge, not by the completion of forensics. CareCloud's letter says it discovered the incident on 16 March and determined the affected data on 24 June. If the first date is discovery, the clock ran out in May. If a company argues that it did not know it had a breach of protected health information until the forensic determination, the clock starts on 24 June and everything that followed was comfortable.
Nothing in the regulation resolves that, and the industry reading has settled on the second.
The letter does not say what was taken
Here is the part that is checkable in thirty seconds and that the coverage noticed without explaining.
Section 164.404(c)(1)(B) requires the notification to include:
A description of the types of unsecured protected health information that were involved in the breach (such as whether full name, social security number, date of birth, home address, account number, diagnosis, disability code, or other types of information were involved).
In the copy filed with California, that element reads:
The disclosure element, as filed
On June 24, 2026, CareCloud determined that the affected data may have included your full name and one (1) or more of the following:<<breachedelements>>approximately <<#>> Rhode Island residents were impacted by this incident
- 01
On June 24, 2026, CareCloud determined tha…: The required disclosure element under 164.404(c)(1)(B) begins here. - 02
<<breachedelements>>: An unpopulated merge field where the data types belong. - 03
approximately <<#>> Rhode Island residents…: The same pattern in the state-specific section, so this is a template throughout rather than a single omission.
To be fair to CareCloud, filing a template with regulators is normal and defensible: 3.7 million people did not all lose the same fields, and the letters that went in the post were presumably populated. This is not evidence that anybody received a letter reading <<breachedelements>>.
It is evidence of something narrower and still worth saying. The only version of this letter a member of the public can read does not state what was taken. The strongest public signal of the data type is the filename the California Attorney General's office assigned to the document, which begins CareCloud_-_SSN_.
What this looks like from the patient's side
Why 3.7 million people are hearing about a company they have never used
- Has a relationship with their clinicThe patient
- The covered entityThe clinic or health system
- Business associate, holds the recordsCareCloud
- 10 to 16 March 2026The AWS environment accessed
The people affected did not choose CareCloud, have not heard of CareCloud, and are now receiving a letter from CareCloud offering identity protection through a fourth company, IDX, redeemable until 17 December 2026.
That is a phishing lure with the serial numbers filed off, and it is genuine. Anyone advising staff or patients this week should expect imitations of exactly this letter, because the real one is indistinguishable in shape from the fake one: an unfamiliar sender, an enrolment code, a deadline and a link.
What to do with this
Take this with you
For anyone running a healthcare estate, or advising one
- Find out which of your business associates hold identifiable patient data and how fast their contracts require them to tell you. The regulation gives them 60 days from discovery, and your own 60 days to notify patients does not start until they do.
- Read your business associate agreements for a defined trigger. The rule says discovery, and discovery is contestable. A contract can say within 72 hours of any suspected unauthorised access, and the good ones do.
- Assume the first news of a breach at a supplier will be a press report, not a letter. Set a standing check on the HHS breach portal for your named suppliers rather than waiting.
- Warn staff and patients about the notification itself. A real letter from a company nobody recognises, carrying an enrolment code and a deadline, is the most convincing phishing template available this month.
- If you are a supplier, populate the merge fields in the copy you file with regulators, or file a covering note that states the data categories. The public record is the only version most people will ever see.
The position
The number in the headline is 3,756,469 and it is the least interesting fact in the story.
What matters is that a rule everybody describes as a 60-day deadline is, in this structure, two 60-day deadlines in sequence, both starting from a word that the regulated party defines in retrospect. A company can take a hundred days to work out what was taken, start the clock at the end of that process, and remain inside the letter of the rule the whole way.
This is the fourth briefing in a fortnight where the published artefact is accurate and answers a narrower question than the reader is asking, after a status page that named components and never a cause, an advisory that said no user action was required and a framework that never named who produces its evidence. Here the artefact is a notification letter, and the field it leaves blank is the one describing what was lost.
Sources
- PrimaryCareCloud notification letter, as filed with the California Attorney GeneralCalifornia Attorney Generalaccessed 2026-08-20
- Primary45 CFR 164.404, Notification to individualseCFRaccessed 2026-08-20
- Primary45 CFR 164.410, Notification by a business associateeCFRaccessed 2026-08-20
- PrimaryBreach portal, reported breaches affecting 500 or more individualsUS Department of Health and Human Services, Office for Civil Rightsaccessed 2026-08-20


