Data breach: CareCloud confirms theft of 3.7m patients’ medical records

3 Min Read

Hackers stole personal information and medical records belonging to more than 3.75 million people in a breach at healthcare technology company CareCloud, the company has confirmed in a filing with federal regulators.

The incident now ranks as the fifth-largest healthcare data breach reported in the U.S. so far this year, according to data compiled by the Department of Health and Human Services.

CareCloud disclosed the March breach in a filing with HHS on Monday. The company reportedly increased the number of affected people in an update Tuesday, although it remains unclear whether the tally could climb again.

The New Jersey-based company provides electronic medical record services to tens of thousands of healthcare providers across the U.S. Its systems handle sensitive patient and billing information for hospitals, physician practices, and other healthcare organizations, putting millions of patients’ data within its reach.

CareCloud first disclosed the attack in March, saying hackers accessed patient medical information stored in one of its cloud environments for six days. Later breach notifications revealed that the attackers exfiltrated data from CareCloud’s Amazon Web Services account, taking a large volume of patient records with them.

The stolen information includes names, postal addresses, Social Security numbers, medical and health information, and government-issued identification numbers such as passport and driver’s license details. The attackers also obtained banking and other financial information.

CareCloud CEO Stephen Snyder has not responded to multiple requests for comment about the breach. Questions remain about whether the company paid a ransom, who oversees its cybersecurity operations, and whether Snyder intends to step down following the incident.

The CareCloud breach adds to a growing list of major healthcare data thefts reported in 2026.

TriZetto disclosed in March that a 2024 breach had exposed data belonging to 3.4 million people. Healthtech billing software provider Craneware also reported a July breach, although the company has not yet disclosed how many people the incident affected.

HHS’ running breach database shows an even larger incident at dental insurance provider DentaQuest. At least 15 million people’s personal and health information has been affected in that breach, making it the largest healthcare data breach reported so far this year.

For healthcare providers, the CareCloud incident is another reminder that outsourcing patient data does not outsource the security risk. When a technology provider holds millions of medical records, one compromised cloud account can quickly become a breach affecting millions of people.

Share This Article
Founder of TechMarge.
Leave a Comment