CareCloud breach exposes 3.7 million patient records

CareCloud confirms 3.7M patients had medical records stolen

Healthcare IT company CareCloud has confirmed that hackers stole the personal and medical information of more than 3.75 million people in a data breach disclosed as the fifth-largest healthcare data theft of 2026. The New Jersey-based company filed the updated figure with the Department of Health and Human Services on August 17, revealing the true scale of an incident first reported in March.

The breach occurred between March 10 and March 16, when an unauthorized party accessed one of CareCloud's Amazon Web Services environments and exfiltrated data from databases. Stolen information includes patients' names, postal addresses, Social Security numbers, medical and health information, government-issued IDs such as passports and driver's licenses, and banking and financial details.

CareCloud provides electronic medical record storage and billing services to tens of thousands of healthcare providers across the United States. The company has not publicly commented on the attack since its initial SEC filing in March. CEO Stephen Snyder has not responded to questions about whether a ransom was paid, who is responsible for cybersecurity, or whether he plans to resign.

The breach notifications sent to affected patients on July 25 offered 12-24 months of identity protection services through IDX. Because CareCloud has no direct relationship with patients — it serves healthcare providers — many impacted individuals are learning of the company for the first time through these notifications.

No ransomware group has claimed responsibility. The breach follows other major healthcare incidents this year, including TriZetto (3.4 million affected) and DentaQuest (15 million affected), highlighting the ongoing vulnerability of the healthcare sector to cyberattacks.

References