CareCloud Acknowledges Data Breach Affecting 3.7 Million Patients’ Medical Records
Hackers have breached the personal and medical information of more than 3.75 million individuals in a security incident involving health data provider CareCloud, as confirmed to federal authorities by the company. This event marks the first official acknowledgment of the breach’s magnitude, now identified as the fifth-largest health data theft observed in 2026.
In a report submitted to the Department of Health and Human Services (HHS) on Monday, CareCloud detailed the data breach that took place in March. The number of affected individuals was reportedly raised in a subsequent update on Tuesday, although it remains unclear if this number will rise any further.
Headquartered in New Jersey, CareCloud provides electronic medical record storage services to thousands of healthcare providers across the United States, thus catering to millions of patients. The company is responsible for managing a considerable volume of patient data and billing information for hospitals, doctors’ offices, and other medical facilities.
Since revealing the breach in March, CareCloud has not issued any public comments regarding the cyberattack. At that time, it disclosed that hackers had accessed patients’ medical data stored in one of its cloud storage systems over a six-day period. Later updates indicated that the attackers extracted data from the company’s Amazon Web Services account, resulting in a significant loss of patient information.
The stolen data includes patients’ names, home addresses, Social Security numbers, and various medical and health-related details. Additionally, the hackers obtained government-issued identification numbers, such as those from passports and driver’s licenses, along with financial and banking information.
CareCloud’s CEO, Stephen Snyder, has not responded to multiple inquiries regarding the incident, including questions about whether the company has paid the hackers, the accountability for cybersecurity at CareCloud, and if Snyder intends to resign due to the circumstances.
The breach at CareCloud follows a series of prominent healthcare data breaches reported this year.
Tech giant TriZetto confirmed a data breach in March 2024 that affected the information of 3.4 million individuals, while an undisclosed number of individuals had their data compromised in a July incident involving healthtech billing software provider Craneware.
As per HHS’s ongoing record of healthcare data breaches, dental insurance leader DentaQuest has experienced the most extensive data breach this year, impacting at least 15 million individuals’ personal and health information.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


