OTHER

CareCloud Discloses Data Breach Affecting Medical Records of 3.7 Million Patients

Over 3.75 million individuals’ personal and medical records have been compromised due to a security breach at health data provider CareCloud, as reported to federal authorities by the company. This incident has now been classified as the fifth-largest health data theft documented in 2026, representing the first formal recognition of its extent.

In a report submitted to the Department of Health and Human Services (HHS) on Monday, CareCloud detailed the data breach that took place in March. The count of affected individuals was reportedly revised in an update on Tuesday, leaving uncertainty about whether this number will increase further.

Based in New Jersey, CareCloud provides electronic medical record storage solutions to numerous healthcare providers across the United States, impacting millions of patients. The company is pivotal in handling vast amounts of patient data and billing information for hospitals, physician offices, and other healthcare establishments.

Since disclosing the breach in March, CareCloud has not made any public comments regarding the cyber incident. Initially, the company disclosed that hackers accessed patient medical data stored in one of its cloud systems for a duration of six days. Further updates indicated that the assailants had extracted information from the company’s Amazon Web Services account, which resulted in significant patient data loss.

The compromised data includes patients’ names, home addresses, Social Security numbers, and various medical and health-related records. Additionally, the hackers have taken government-issued identification numbers, such as those from passports and driver’s licenses, along with financial and banking information.

CareCloud’s CEO, Stephen Snyder, has not responded to multiple queries regarding the incident, including whether the company has made payments to the hackers, who is accountable for cybersecurity at CareCloud, and whether he intends to step down in light of the breach.

The incident at CareCloud occurs against the backdrop of several notable healthcare data breaches reported this year.

In March 2024, tech giant TriZetto confirmed a data breach affecting 3.4 million individuals, while an incident in July involving healthtech billing software provider Craneware compromised an unspecified number of individuals’ data.

According to HHS’s ongoing record of healthcare data breaches, DentaQuest, a leader in dental insurance, has suffered the largest breach this year, impacting at least 15 million individuals’ personal and health information.

By purchasing through links in our articles, we may earn a small commission. This does not influence our editorial independence.