Skip to main content

August 12, 2026

When Your EHR Vendor Gets Breached, Your Practice Pays

The CareCloud breach exposed 345,000 patient records. What medical practices should know about vendor risk, BAAs, and their own notification duties.

What happened at CareCloud

CareCloud, a cloud EHR and billing platform used by more than 45,000 healthcare providers, began notifying patients in early August that hackers had spent at least six days inside one of its EHR environments back in March. The stolen data is about as sensitive as it gets: names, Social Security numbers, government IDs, bank and payment card details, and medical and insurance information. At least 345,000 people are receiving letters, a number TechCrunch reports is likely to grow as state filings continue.

Two details deserve attention. The intrusion was detected in mid-March, and patient notifications began August 3, roughly four and a half months later. And no ransomware group has claimed the attack, which usually means the data was taken for quiet resale rather than a public shakedown.

The practice didn’t get hacked. It still pays.

Here is the part that matters if you run a medical, dental, or veterinary practice: the providers whose patients got those letters did nothing wrong. Their software vendor was breached. The patients will not make that distinction. They call the front desk, they ask why their Social Security number is on the dark web, and some of them quietly find another provider.

That is the shape of modern healthcare risk. Practices have gotten reasonably good at locking their own doors while their most valuable data sits with a vendor whose security they have never seen, governed by a business associate agreement nobody has read since it was signed.

Stuck on something like this right now?

Talk it through with a real US-based engineer, 24/7, no phone trees: (407) 587-0089.

Book a Free Strategy Session

What HIPAA actually expects when a vendor is breached

The rules anticipate this chain of events. A business associate must notify the affected practice of a breach without unreasonable delay, and no later than 60 days after discovery, under 45 CFR 164.410. The practice, as the covered entity, generally owes its patients notice within 60 days of discovery under 45 CFR 164.404.

Those are ceilings, not targets. A vendor that takes the full window, then a practice that takes another full window, produces exactly the kind of four-month gap patients read about in the CareCloud coverage. Your business associate agreement can demand faster notice than the regulation does, and the time to negotiate that is before anything happens.

The detection gap is the real lesson

Look at the timeline again. The intruders were inside for roughly six days in March. Detection happened quickly by industry standards, yet patients still learned about it in August, after forensics, scoping, and state-by-state filings ground through their necessary paces. That middle part is normal, and it is slow everywhere.

What a practice controls is its own detection window. Most small practices have nobody reading access logs, so a compromised account or an odd data pull gets discovered when something visibly breaks, or when a patient calls. Every downstream obligation, the 60-day clocks included, starts from discovery. Finding trouble in hours instead of months shrinks the legal exposure, the forensics bill, and the number of patients affected at all.

Five questions to ask your EHR vendor this month

Send these to your account rep. The answers belong in a folder your practice manager can find on a bad day.

  1. What does our business associate agreement say about breach notification timing, and can we shorten it below the 60-day regulatory ceiling?
  2. Where is our data hosted, and how is it separated from your other customers?
  3. Is multifactor authentication enforced on every account that can touch our records, including your own support staff?
  4. What activity logs exist for our data, and who reviews them?
  5. When was your last independent security assessment, and will you share the summary?

A vendor that answers quickly and specifically is telling you something. So is a vendor that does not.

Tighten your side of the chain

None of this excuses the practice-side basics, because attackers do not care whose fault the open door is. The work that matters: keep an inventory of every vendor that touches patient data and confirm a current BAA exists for each, give staff least-privilege accounts inside the EHR instead of shared logins, enforce multifactor authentication everywhere, close accounts the day someone leaves, and have an incident plan that includes the scenario where the breach is your vendor’s. The human-run security operations behind our cybersecurity service add the piece most practices lack: someone actually watching sign-in activity and access patterns so a problem surfaces in hours, not months.

There is an insurance angle too. Cyber carriers now ask direct questions about vendor management, and a documented BAA inventory plus an incident plan that names the vendor-breach scenario makes renewal season shorter and cheaper. Write it down before you need it, and walk through it once a year the way you would a fire drill. A plan nobody has rehearsed is a document, not a plan.

For Central Florida practices

Cyber Command provides IT support for healthcare practices across Orlando, Tampa Bay, and Jacksonville, from our headquarters in Winter Springs. If the CareCloud story made you wonder what your own vendor exposure looks like, that is a healthy instinct. Talk to a real person and we will walk through your vendor list, your BAAs, and the practice-side controls together. The first conversation costs nothing.

This article is for general informational purposes only and is not legal, compliance, insurance, or other professional advice. Threats, technologies, and regulations change quickly; confirm current requirements with your own advisors before acting. See our full disclaimer.