CareCloud Reports Data Breach Affecting Medical Records of 3.7 Million Patients
A security breach at CareCloud, a provider of health data services, has led to the exposure of personal and medical data for more than 3.75 million individuals. This incident has been reported to federal authorities and is now considered the fifth-largest health data theft documented in 2026, underscoring its severity.
In a report to the Department of Health and Human Services (HHS) on Monday, CareCloud detailed the breach that took place in March. An update released on Tuesday indicated a revision in the number of affected individuals, although it remains uncertain if this figure will increase.
Based in New Jersey, CareCloud provides electronic medical record storage solutions to various healthcare providers throughout the United States, impacting millions of patients. The company is vital in managing large volumes of patient information and billing data for hospitals, physician practices, and other healthcare organizations.
Since disclosing the breach in March, CareCloud has restricted public comments regarding the cyber incident. Initial reports indicated that hackers accessed patient medical data stored in one of its cloud systems for six days. Later updates suggested that the attackers extracted data from the company’s Amazon Web Services account, resulting in substantial patient data loss.
The compromised data includes patients’ names, home addresses, Social Security numbers, and a variety of medical and health-related records. Furthermore, the hackers obtained government-issued identification numbers, such as those from passports and driver’s licenses, alongside financial and banking details.
Stephen Snyder, CEO of CareCloud, has not responded to numerous inquiries regarding the situation, including whether the company has made payments to the hackers, who oversees cybersecurity at CareCloud, or if he intends to resign following the breach.
This incident at CareCloud coincides with several other significant healthcare data breaches reported this year.
In March 2024, technology giant TriZetto announced a data breach affecting 3.4 million individuals, while a July incident involving healthtech billing software provider Craneware compromised an undisclosed number of individuals’ data.
According to HHS’s ongoing record of healthcare data breaches, DentaQuest, a leading dental insurance provider, has suffered the largest breach this year, affecting at least 15 million individuals’ personal and health information.
By purchasing through links in our articles, we may earn a small commission. This does not influence our editorial independence.


