P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

AI Security

CareCloud's breach reached 3.75 million people and took 131 days to reach them. The rule it was measured against sets 60 days twice

The HIPAA deadline everyone quotes is two consecutive 60-day windows, both starting at a word the regulated party defines in retrospect. And the letter filed with California leaves the field describing what was taken as an unfilled merge placeholder.

By Parminder Kumar Sharma · · 6 min read

A dark navy chart headed The rule says 60 days, it says it twice. Two cyan outlined bars each labelled 60 days run consecutively, the first from associate to covered entity and the second from covered entity to you. Beneath them a longer red bar reads 131 days actually elapsed. A timeline below marks 16 March discovery, 24 June data determined, and 25 July letters.

What the notification letter actually says

CareCloud disclosed on 20 August 2026 that a breach first reported to the Securities and Exchange Commission in March affected 3,756,469 individuals. The company is a healthcare technology provider, publicly traded, supplying electronic health records, billing and revenue-cycle services to healthcare organisations.

The document worth reading is not the coverage. It is the notification letter CareCloud filed with the California Attorney General, which is public, and which sets out its own timeline in its own words.

On March 16, 2026, CareCloud experienced a network disruption in its CareCloud Health division that impacted one of its electronic health record environments.

The investigation determined that, between March 10 and March 16, 2026, an unauthorized third party accessed one of CareCloud's [environments].

On June 24, 2026, CareCloud determined that the affected data may have included your full name and one (1) or more of the following.

Three dates, from the company: discovery on 16 March, a determination of what was taken on 24 June, and letters from 25 July. That is 131 days from the disruption to the first letter.

The rule sets sixty days, and sets it twice

Two statutory windows, and the time that actually passed

THE RULE SETS 60 DAYS. TWICE. FROM A WORD.164.410(b): associate tells the covered entity164.404(b): covered entity tells you131 days actually elapsedAccess beginsPer the investigationDiscoveryNetwork disruption. The clock starts hereData determined100 days laterLetters go out131 days laterBoth sections start the clock at “discovery”, defined as the first day the breach is known or would have been knownwith reasonable diligence. That word, not the number 60, is what decides whether any of this was late.
Windows from 45 CFR 164.410(b) and 164.404(b), read at eCFR on 20 August 2026. Dates from CareCloud's own notification letter filed with the California Attorney General. The bands are drawn as the rule allows them to run, not as an accusation: whether either was exceeded depends on facts about discovery that are not public.

The HIPAA Breach Notification Rule sets the same deadline in two places, because a company like CareCloud is usually a business associate rather than the entity holding the patient relationship.

The two clocks, quoted

SectionWho tells whomThe deadline
164.410(b)Business associate tells the covered entityWithout unreasonable delay and in no case later than 60 calendar days after discovery of a breach
164.404(b)Covered entity tells the individualWithout unreasonable delay and in no case later than 60 calendar days after discovery of a breach
164.410(a)(2)Both, on when the clock startsThe first day on which such breach is known, or by exercising reasonable diligence would have been known
Text quoted verbatim from eCFR, title 45, current as of 18 August 2026. The definition of discovery is identical in both sections and is the operative language in both.

Run those consecutively and 120 days is available before anybody has done anything unusual. That accounts for most of the gap, and it is why the honest version of this story is not that CareCloud broke the rule. It is that the deadline is anchored to a word.

Discovery is defined by knowledge, not by the completion of forensics. CareCloud's letter says it discovered the incident on 16 March and determined the affected data on 24 June. If the first date is discovery, the clock ran out in May. If a company argues that it did not know it had a breach of protected health information until the forensic determination, the clock starts on 24 June and everything that followed was comfortable.

Nothing in the regulation resolves that, and the industry reading has settled on the second.

The letter does not say what was taken

Here is the part that is checkable in thirty seconds and that the coverage noticed without explaining.

Section 164.404(c)(1)(B) requires the notification to include:

A description of the types of unsecured protected health information that were involved in the breach (such as whether full name, social security number, date of birth, home address, account number, diagnosis, disability code, or other types of information were involved).

In the copy filed with California, that element reads:

The disclosure element, as filed

On June 24, 2026, CareCloud determined that the affected data may have included your full name and one (1) or more of the following:<<breachedelements>>approximately <<#>> Rhode Island residents were impacted by this incident
  1. 01On June 24, 2026, CareCloud determined tha…: The required disclosure element under 164.404(c)(1)(B) begins here.
  2. 02<<breachedelements>>: An unpopulated merge field where the data types belong.
  3. 03approximately <<#>> Rhode Island residents…: The same pattern in the state-specific section, so this is a template throughout rather than a single omission.
From the sample notification letter filed with the California Attorney General. The double angle brackets are mail-merge placeholders. Filing a template is ordinary practice, because each recipient receives a different list. The consequence is still that the public copy does not answer the question it exists to answer.

To be fair to CareCloud, filing a template with regulators is normal and defensible: 3.7 million people did not all lose the same fields, and the letters that went in the post were presumably populated. This is not evidence that anybody received a letter reading <<breachedelements>>.

It is evidence of something narrower and still worth saying. The only version of this letter a member of the public can read does not state what was taken. The strongest public signal of the data type is the filename the California Attorney General's office assigned to the document, which begins CareCloud_-_SSN_.

What this looks like from the patient's side

Why 3.7 million people are hearing about a company they have never used

  1. Has a relationship with their clinicThe patient
  2. The covered entityThe clinic or health system
  3. Business associate, holds the recordsCareCloud
  4. 10 to 16 March 2026The AWS environment accessed
The structure is ordinary and is how most healthcare technology works. It is also why breach notification at this layer arrives late, arrives from an unfamiliar sender, and is easy to mistake for a phishing attempt.

The people affected did not choose CareCloud, have not heard of CareCloud, and are now receiving a letter from CareCloud offering identity protection through a fourth company, IDX, redeemable until 17 December 2026.

That is a phishing lure with the serial numbers filed off, and it is genuine. Anyone advising staff or patients this week should expect imitations of exactly this letter, because the real one is indistinguishable in shape from the fake one: an unfamiliar sender, an enrolment code, a deadline and a link.

What to do with this

Take this with you

For anyone running a healthcare estate, or advising one

  • Find out which of your business associates hold identifiable patient data and how fast their contracts require them to tell you. The regulation gives them 60 days from discovery, and your own 60 days to notify patients does not start until they do.
  • Read your business associate agreements for a defined trigger. The rule says discovery, and discovery is contestable. A contract can say within 72 hours of any suspected unauthorised access, and the good ones do.
  • Assume the first news of a breach at a supplier will be a press report, not a letter. Set a standing check on the HHS breach portal for your named suppliers rather than waiting.
  • Warn staff and patients about the notification itself. A real letter from a company nobody recognises, carrying an enrolment code and a deadline, is the most convincing phishing template available this month.
  • If you are a supplier, populate the merge fields in the copy you file with regulators, or file a covering note that states the data categories. The public record is the only version most people will ever see.

The position

The number in the headline is 3,756,469 and it is the least interesting fact in the story.

What matters is that a rule everybody describes as a 60-day deadline is, in this structure, two 60-day deadlines in sequence, both starting from a word that the regulated party defines in retrospect. A company can take a hundred days to work out what was taken, start the clock at the end of that process, and remain inside the letter of the rule the whole way.

This is the fourth briefing in a fortnight where the published artefact is accurate and answers a narrower question than the reader is asking, after a status page that named components and never a cause, an advisory that said no user action was required and a framework that never named who produces its evidence. Here the artefact is a notification letter, and the field it leaves blank is the one describing what was lost.

Sources

  1. PrimaryCareCloud notification letter, as filed with the California Attorney GeneralCalifornia Attorney Generalaccessed 2026-08-20
  2. Primary45 CFR 164.404, Notification to individualseCFRaccessed 2026-08-20
  3. Primary45 CFR 164.410, Notification by a business associateeCFRaccessed 2026-08-20
  4. PrimaryBreach portal, reported breaches affecting 500 or more individualsUS Department of Health and Human Services, Office for Civil Rightsaccessed 2026-08-20

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.