OTHER

CareCloud Discloses Data Breach Affects 3.7 Million Patients’ Medical Records

A security breach at CareCloud, a provider of health data services, has led to the exposure of personal and medical information for more than 3.75 million individuals. This incident has been reported to federal agencies and is now acknowledged as the fifth-largest health data theft recorded in 2026, underscoring its severity.

In a report to the Department of Health and Human Services (HHS) on Monday, CareCloud detailed the breach that took place in March. An update shared on Tuesday indicated a revision in the number of affected individuals, although it remains uncertain if this figure may increase further.

Based in New Jersey, CareCloud provides electronic medical record storage solutions to various healthcare providers across the United States, impacting millions of patients. The company is essential in managing vast amounts of patient information and billing data for hospitals, physician offices, and other healthcare entities.

Since announcing the breach in March, CareCloud has refrained from making public comments regarding the cyber incident. Initially, reports indicated that hackers had access to patient medical data stored in one of its cloud systems for a duration of six days. Follow-up updates revealed that the attackers extracted information from the company’s Amazon Web Services account, resulting in significant patient data loss.

The compromised data includes patients’ names, home addresses, Social Security numbers, and various medical and health-related records. Moreover, the hackers obtained government-issued identification numbers, encompassing those from passports and driver’s licenses, in addition to financial and banking information.

Stephen Snyder, CEO of CareCloud, has not responded to numerous questions regarding the incident, including whether the company has made any payments to the hackers, who is accountable for cybersecurity at CareCloud, or if he intends to resign following the breach.

This situation at CareCloud is unfolding amidst several other significant healthcare data breaches reported this year.

In March 2024, tech giant TriZetto disclosed a data breach affecting 3.4 million individuals, while a July incident involving the healthtech billing software provider Craneware compromised an undisclosed number of individuals’ data.

According to HHS’s ongoing record of healthcare data breaches, DentaQuest, a leading dental insurance provider, has suffered the largest breach this year, affecting at least 15 million individuals’ personal and health information.

By purchasing through links in our articles, we may earn a small commission. This does not influence our editorial independence.