Skip to content
article

What the CareCloud Breach Means for Every Medical and Dental Practice in Texas

A major healthcare technology vendor was breached, exposing 3.7 million patient records. Here is what medical and dental practices should take from it.

September 8, 2026
3 min read
AstraLink Connect Team

In August, CareCloud, a healthcare technology company that provides electronic health record and billing software to tens of thousands of medical practices across the country, confirmed that a breach discovered in March had exposed the records of more than 3.7 million patients. The stolen data reportedly included names, addresses, and in many cases financial and medical details.

Here is the detail worth sitting with. CareCloud is not a hospital or a clinic. It is a vendor, a piece of software many practices use every day without thinking twice about it. The practices affected did not necessarily do anything wrong. Their patients’ information was exposed because a company several steps removed from the exam room had a security failure in one of its cloud environments.

This is not an isolated story. Similar vendor breaches this year have hit other health technology platforms used widely across the industry, each one demonstrating the same uncomfortable pattern: a single vendor failure can expose patient data at practices that never had a breach of their own.

For a medical or dental practice, this points to two things worth doing now.

First, know what your vendors are actually doing with your patients’ data. Practice management software, billing platforms, and scheduling tools all touch protected health information, and HIPAA does not distinguish between a breach that happened on your servers and one that happened on a vendor’s. Your practice is still expected to have understood the risk and taken reasonable steps to manage it.

Second, treat AI tools the same way

A growing number of practices use AI assistants to draft notes, summarize charts, or speed up documentation. If a staff member pastes patient information into a public AI tool to save time, that information leaves your control the same way it would through a vendor breach, except nobody may ever tell you it happened.

AstraLink Connect’s AI Protect is built for exactly this second risk: visibility into which AI tools are actually being used in your practice, and the ability to stop sensitive patient information before it leaves, without slowing your staff down. Connect handles the network side, watching for the kind of unusual activity that often signals a vendor connection has gone wrong.

The CareCloud breach will not be the last vendor incident to touch a Texas medical or dental practice this year. The practices in the best position are the ones who already know what is connected to their systems, rather than finding out from a notification letter.

See what is actually connected to your practice. Request a Verify assessment from AstraLink Connect.

Tags

news medical-dental texas
Back to blog