Eight hours. Remember that number from the headline. The Record, 19 Aug 2026: CareCloud told HHS that about 3.76 million people were affected after an attacker spent eight hours inside one of its electronic health record environments. The headcount is for lawyers. The eight hours is for operators.
What can a patient person do in eight hours in a medical SaaS tenant. Export. Persist. Look at the next tenant if isolation is soft. The press release will say "unauthorized access." The useful sentence is "we did not see them for a workday."
What we put on the wire
New admin sessions. Bulk export jobs. Identity provider anomalies. A box that starts talking to a country you do not bill in. Managed security services for a healthcare-adjacent app is those tickets with a human who calls before hour two, not a PDF at hour twenty.
The Record the same day: Latvian officials resigned after a road-agency breach tied to roughly two-thirds of the country. Different sector. Same political physics. When the dwell is long enough, people lose jobs. SMB clinics feel that as a lost contract, not a minister on TV.
If you ship anything that looks like a vault or an audit log, you also need someone who can reject the log. That is someone else has to sign the tree. Monitoring is the cheap cousin: see the session while it is still a session.
Remember the $0 line item called "we will notice." Eight hours says that line item was fiction. We will watch the tenant boundary and the export path. Request a quote if your current detect story is the vendor's status page.
Patch helps. Segmentation helps. None of it matters if the first alert is a lawyer.
Sources
- Electronic health record company CareCloud says 3.7 million people affected by breach — The Record, 19 Aug 2026
- Latvian officials resign after cyberattack exposes data on 1.2 million people — The Record, 19 Aug 2026

