CareCloud Breach Hits 345,000 & CISA Rewrites the SBOM Rules (08/03/2026)

August 3, 2026
CareCloud Breach Hits 345,000 & CISA Rewrites the SBOM Rules (08/03/2026)
Key Intel / TL;DR
  • CareCloud began notifying more than 345,000 patients about a March breach, 140 days after it confirmed what was taken.
  • CareCloud serves more than 45,000 providers, so the notification obligation lands on client practices that had no part in the incident.
  • CISA, the FBI, the NSA, and 15 international authorities replaced the 2021 SBOM minimum elements with ten new data fields and eight revised components.
  • AnMed is still restoring systems after a cyberattack closed 83 facilities, and is now warning patients about communications claiming to come from the health system.
  • Colorado's attorney general settled with a rent payment processor over an unlawful 3.25% fee, under the state's surcharge and junk fees statutes.

The CareCloud notification is the one to read carefully, because the dates do the talking: attackers were in during March, the company confirmed the scope in June, and the letters went out today. Every practice that outsourced billing to them now owns a notification obligation it did not create. Meanwhile CISA replaced the SBOM baseline that has governed software transparency since 2021, which changes what you can reasonably ask a vendor for.

Top 4 Critical Compliance Alerts

1. A Billing Vendor’s March Breach Becomes 345,000 Notifications Today

CareCloud has begun notifying at least 345,000 individuals, including 270,197 Texas residents, about data stolen between March 10 and 16. The company detected a network disruption on March 16, confirmed the scope on June 24, and started mailing letters on August 3. Stolen data varies by person and includes names, addresses, dates of birth, Social Security numbers, government ID numbers, financial account and payment card numbers, and health insurance information. CareCloud provides cloud EHR, revenue cycle management, and clinical documentation to more than 45,000 providers. It is offering 24 months of identity theft protection. HIPAA Journal

Operator Note: 140 days passed between confirming the scope and notifying people. If your business associate agreement does not put a clock on the vendor’s confirmation and notification steps separately, you inherit their timeline and the regulator asks you about it. Check what your agreement actually says this week.

2. CISA and 17 Partners Replace the 2021 SBOM Baseline

CISA, the FBI, and the NSA, together with 15 international cybersecurity authorities, published updated minimum elements for a Software Bill of Materials, replacing the 2021 NTIA guidance. The update adds ten data fields and revises eight existing components to clarify scope, plus five minor alignment changes. The agencies say tooling has matured enough to support more detailed supply chain information than the original allowed. It applies to all software, with the note that AI systems and SaaS may need additional requirements. HIPAA Journal

Operator Note: This raises the floor of what you can reasonably demand in procurement. If your vendor questionnaire still points at the 2021 elements, it now asks for less than the baseline, and a vendor answering it honestly can meet your standard while falling short of the current one.

3. AnMed Is Still Recovering, and Now Warning Patients About Fake Contacts

The Anderson, South Carolina health system says it continues restoring systems after the cyberattack that closed 83 facilities, and is warning patients about communications claiming to come from AnMed. HIPAA Journal

Operator Note: The window after a publicized incident is when impersonation works best, because patients are expecting contact and cannot verify through the systems that are down. Your incident plan needs a pre-agreed channel people can trust when the usual ones are offline, decided before you need it.

4. Colorado Settles With a Rent Payment Processor Over Junk Fees

The Colorado attorney general announced on July 29 that a rent payment processing company settled allegations it violated the state’s surcharge and junk fees statutes by charging an unlawful 3.25% “certified funds” fee on credit and debit card payments. JD Supra

Operator Note: Payment surcharge rules are state law and they differ, so a single national fee schedule is the fastest way to be out of compliance in a handful of jurisdictions at once. If you add any fee at checkout, it belongs on the same review cycle as your privacy notices.


The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Dusten Trounce
Director of Physical Security
Dusten Trounce
The Growth Architect.

A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)