CareCloud Data Breach Lawsuit, Were You Affected? — Arslanian v. CareCloud Inc., No. 1:2026-cv-23048
If a letter from CareCloud landed in your mailbox this summer telling you your Social Security number, medical records, or bank details may be in a stranger’s hands, you weren’t imagining how serious that is. CareCloud, Inc. is now facing a consolidated class action, Arslanian v. CareCloud Inc., No. 1:2026-cv-23048, in Florida federal court over a breach that exposed data belonging to more than 3.75 million patients nationwide. Here’s what that actually means for you.
CareCloud Data Breach Lawsuit — Key Facts
| Lawsuit Filed | April 29, 2026 (consolidated complaint filed June 22, 2026) |
| Defendant | CareCloud, Inc. and CareCloud Health, Inc. |
| Alleged Harm | Unauthorized access to and exfiltration of patient data from a CareCloud AWS environment |
| Law Alleged | UNVERIFIED — the specific causes of action pled in the consolidated complaint require a PACER subscription to confirm; only the docket entry (personal injury, diversity jurisdiction) was verifiable from public records |
| Who Is Affected | 3,756,469 individuals nationwide who received a CareCloud breach notice |
| Court & Case Number | U.S. District Court, Southern District of Florida — No. 1:2026-cv-23048 |
| Current Stage | Consolidated; interim class counsel appointed June 12, 2026; consolidated amended complaint pending before Judge Roy K. Altman |
| Lead Plaintiff Deadline | N/A — interim class counsel already appointed |
| Settlement Status | No settlement. No claim form. |
| Last Updated | August 28, 2026 |
Who Is CareCloud and Why Are They Being Sued for the Data Breach?
CareCloud runs the cloud-based electronic health record and billing systems that more than 40,000 medical practices use to store patient charts, insurance details, and payment information. That concentration is exactly what made the company a target — one compromised AWS environment gave a hacker a path into records covering millions of patients across dozens of unrelated clinics. The lawsuit argues CareCloud held that data as a paid vendor and had a duty to keep it secured, a duty plaintiffs say it failed.
What Did CareCloud Do to Patients Between March 10 and March 16, 2026?
An unauthorized third party got into one of CareCloud’s Amazon Web Services environments between March 10 and March 16, 2026, and claimed to have pulled data out of the databases inside it. CareCloud reported the incident to the SEC on March 24, calling it a “material cybersecurity incident” under Item 1.05 of Form 8-K — the rule that forces public companies to tell investors about hacks serious enough to matter financially.

It took CareCloud until June 24, 2026 to finish sorting out whose data was actually taken and what it included. Depending on the person, the stolen files may hold full names, home addresses, Social Security numbers, driver’s license numbers, financial account numbers, credit or debit card numbers, and medical or health insurance information. Notification letters didn’t start going out until July, nearly four months after the intrusion began.
This isn’t the first time a healthcare data breach has ended up in front of a judge, and it won’t be the last. IBJI’s $4 million data breach settlement shows what typically happens once a case like this reaches a resolution — though CareCloud’s is nowhere near that point yet.
That’s roughly a four-month gap between the breach and the moment most patients found out. Plenty of time for stolen data to already be circulating before anyone got a warning.
Are You Part of the CareCloud Data Breach Lawsuit?
Here’s exactly how to know if this case includes you.
- Patients who received a written notice from CareCloud dated July 2026 or later
- Anyone whose medical provider used CareCloud’s EHR, billing, or practice management systems between March 10 and March 16, 2026
- Individuals among the 3,756,469 people CareCloud reported to HHS on August 17, 2026
- Those who haven’t received a letter yet but know their provider runs on CareCloud’s platform
If your provider has never used CareCloud’s systems, or you never received a breach notice and can’t confirm your information was in the affected environment, you’re likely not part of this case.
CareCloud Patients Outside Florida — Are You Still Covered?
Yes. CareCloud serves healthcare providers in all 50 states, and this case sits in federal court, not Florida state court — so it applies nationwide, not just to Florida residents. Where you live doesn’t determine your eligibility. Whether your data sat inside the breached CareCloud environment does.
Settled cases like Cardiovascular Consultants’ $3.85 million health data settlement followed a similar path — patients who received a breach notice were automatically part of the class, no extra paperwork required just to qualify.
If your provider used CareCloud and you got a notice this summer, you don’t need to do anything special to be a potential class member. You already are one.
Not sure if you qualify for the CareCloud data breach lawsuit? A free consultation with a data privacy attorney can help you understand your options while the litigation is still in its early stages.
What Are CareCloud Patients Asking the Court to Award?
No money yet. No claim form yet. The consolidated complaint asks the court for damages covering things like credit monitoring costs, time spent dealing with the fallout, and losses tied to identity theft or fraud — plus an order requiring CareCloud to tighten its security going forward.
What Could CareCloud Patients Receive If This Settles?
Impossible to predict right now. Recent healthcare data breach settlements have ranged from flat no-proof payments around $50 up to $5,000 for people who can document actual losses, but the final number in this case depends on how many patients file, what the evidence shows, and how negotiations play out. Talk to a data privacy attorney before deciding whether to wait on the class case or pursue something on your own.
Cases like this typically take a year or more to reach a settlement. CareCloud’s is only a few months in, so patience is genuinely part of the process here.
What Should CareCloud Patients Do Right Now?
- Most patients don’t need to file anything to be included in the case. No panic.
- Save these documents now: your CareCloud breach notice letter, credit card or bank statements showing anything suspicious, and records of time spent freezing credit or replacing cards.
- Write down your losses — when you noticed something wrong, what it cost you, and why you think it’s connected to this breach.
- Lead plaintiff deadline: not applicable here. The court already appointed interim class counsel on June 12, 2026, so there’s no separate deadline to step forward as a named plaintiff.
- Monitor the docket. The case is Arslanian v. CareCloud Inc. et al., No. 1:2026-cv-23048, in the U.S. District Court for the Southern District of Florida.
- Consider an individual claim if your losses are significant. A data privacy attorney can tell you whether that route makes more sense than waiting on the class case to develop.
CareCloud Data Breach Lawsuit — Full Timeline
| Milestone | Date |
| Unauthorized access begins | March 10, 2026 |
| Network disruption detected | March 16, 2026 |
| CareCloud restores full functionality | March 16, 2026 (evening) |
| SEC Form 8-K filed | March 24, 2026 |
| First class action complaint filed | April 29, 2026 |
| Cases consolidated | June 12, 2026 |
| Consolidated amended complaint filed | June 22, 2026 |
| CareCloud completes data review | June 24, 2026 |
| Notification letters sent | July 2026 |
| HHS breach portal listing confirmed | August 17, 2026 |
| Next scheduled hearing | UNVERIFIED — not listed in publicly available docket entries reviewed |
| Expected resolution | UNVERIFIED — no timeline has been set |
CareCloud Data Breach — Frequently Asked Questions, No. 1:2026-cv-23048
Is there a class action lawsuit against CareCloud for the data breach right now?
Yes. Patients filed suit within weeks of CareCloud’s March 2026 breach disclosure, and the court consolidated the cases into one complaint, Arslanian v. CareCloud Inc., No. 1:2026-cv-23048, in the Southern District of Florida on June 12, 2026.
Do I need to do anything right now to be part of the CareCloud lawsuit?
No. If your data sat inside the breached CareCloud environment, you’re likely already part of the proposed class automatically. You only need to act if you want to pursue an individual claim instead.
When will the CareCloud data breach case settle?
There’s no timeline yet. The consolidated complaint was only filed in June 2026, and cases like this typically take a year or longer to reach a settlement, sometimes more.
Can I file my own lawsuit against CareCloud instead of joining the class?
Yes, if your documented losses are significant enough to justify it. Talk to a data privacy attorney about whether an individual claim against CareCloud fits your situation before the case moves further along.
How will I find out if the CareCloud lawsuit settles?
If a settlement happens, notice typically goes out by mail or email to the same list CareCloud already used for the breach notification — the 3,756,469 individuals it reported to HHS.
What does “interim class counsel” mean for the CareCloud case, and why does it matter?
On June 12, 2026, Judge Roy K. Altman approved attorneys to represent the consolidated group of CareCloud plaintiffs going forward. That’s different from a securities case’s “lead plaintiff” deadline — patients don’t need to apply to be represented here.
What data did the CareCloud breach expose?
Depending on the person, CareCloud says the stolen files may include full names, addresses, Social Security numbers, driver’s license numbers, financial account numbers, card numbers, and medical or health insurance details.
How much could CareCloud patients get if this case settles?
Too early to say with any confidence. Comparable healthcare data breach settlements have paid anywhere from roughly $50 with no proof required up to $5,000 for documented losses, but CareCloud’s case hasn’t reached that stage yet.
Sources Used in This CareCloud Data Breach Article
- Court Docket — Arslanian v. Carecloud Inc et al, No. 1:2026-cv-23048, U.S. District Court, S.D. Fla. (retrieved via Justia Dockets & Filings, PACER-sourced): https://dockets.justia.com/docket/florida/flsdce/1:2026cv23048/713135
- U.S. Securities and Exchange Commission — CareCloud, Inc. Form 8-K, Item 1.05 Material Cybersecurity Incidents, filed March 27, 2026: https://www.sec.gov/Archives/edgar/data/1582982/000149315226013239/form8-k.htm
- HIPAA Journal — “CareCloud Data Breach Affects 3.75 Million Individuals,” August 2026: https://www.hipaajournal.com/carecloud-data-breach/
- CareCloud, Inc. Notice of Data Breach letter, filed with the South Carolina Department of Consumer Affairs, 2026: https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2026/Consumer%20Letter%20-%20CareCloud,%20Inc..pdf
Researched and written by Israr Ahmad, legal content researcher and founder of AllAboutLawyer.com. All facts verified against official court records and the sources named above on August 28, 2026. Last Updated: August 28, 2026.
This article is for informational purposes only and does not constitute legal advice. Laws vary by state and individual circumstances differ. For advice about your specific situation, consult a qualified attorney.
About the Author
Israr Ahmad is a legal content researcher with 4+ years of experience covering class action settlements and consumer rights cases. He has researched and published coverage of 2,500+ settlements using verified court records, settlement administrator filings, and government sources. Learn more about Israr.
