XML 30 R18.htm IDEA: XBRL DOCUMENT v3.26.1
COMMITMENTS AND CONTINGENCIES
3 Months Ended
Mar. 31, 2026
Commitments and Contingencies Disclosure [Abstract]  
COMMITMENTS AND CONTINGENCIES

 

9.COMMITMENTS AND CONTINGENCIES

 

Legal Proceedings — A former customer had a dispute with the Company that was based on services before and after the account was acquired in an acquisition. A complaint was filed in Massachusetts State Court, Essex County in February 2018. Under the terms of the purchase agreement, the Company’s liability, if any, was solely and expressly limited to damages related to its handling of the account at issue. The parties participated in formal mediation and at that time, Plaintiff’s starting settlement demand was over $2 million. The mediation was not successful. The Company made an offer of $100,000 in December 2024 to settle the suit, which was accepted. The settlement amount was recorded in accrued expenses at December 31, 2024 in the condensed consolidated balance sheet. A settlement agreement with mutual releases was signed by the parties in January 2025 and payment was made in February 2025.

 

A dispute occurred with a former customer regarding previous services rendered and they filed a complaint in New York Supreme Court, Onondaga County in January 2024. During settlement communications, Plaintiff’s initial settlement demand was over $2.5 million. During ongoing settlement communications, the Company made an offer of $29,000 in March 2025, which was accepted. A settlement agreement with mutual releases was signed by the parties in May 2025 and payment was made in June 2025.

 

Cybersecurity Incident — On March 16, 2026, the Company experienced a temporary network disruption in its CareCloud Health division that affected functionality and data access in one of its six electronic health record environments for approximately eight hours, after which all functionality and data access were fully restored. Upon discovery, the Company notified its cybersecurity carrier and engaged a leading cyber response advisory team within a Big Four accounting firm to secure the environment and conduct a comprehensive forensic investigation.

 

The incident was contained on the day of discovery and is believed to have been limited to the CareCloud Health environment, with no impact on the Company’s other platforms, divisions, systems, data, or environments. The Company believes the incident was caused by an unauthorized third party who gained access to the system.

 

The affected environment stores patient information. The Company continues to assess the extent to which patient information or other data was accessed and/or exfiltrated, including the categories and quantity of any such data. Subsequent forensic analysis indicates that a yet-to-be-determined amount of data was exfiltrated, and that initial unauthorized access occurred approximately one week before the March 16th incident.

 

All affected systems have been fully restored and the Company believes the threat actor no longer has access. The Company is working with its outside cybersecurity experts to reinforce its information technology systems and prevent future unauthorized access. The Company currently believes its cybersecurity insurance coverage is sufficient for any potential losses and will provide updated disclosures as additional information becomes available and the full scope of the incident is determined.

 

To date, we have been served with two class action complaints from patients that were allegedly impacted by events surrounding the incident and the Company anticipates receiving other similar complaints as are customarily filed when there is such an incident.

 

From time to time, we may become involved in other legal proceedings arising in the ordinary course of business. We are not presently a party to any legal proceedings that, in the opinion of management, would individually or in the aggregate have a material adverse effect on our business, consolidated results of operations, financial position, or cash flows.