CareCloud admits over 3.7 million patients' records were stolen in breach
CareCloud confirmed that hackers accessed the personal and medical data of more than 3.75 million individuals, making it the fifth-largest health-data theft of 2026.
CareCloud reported to the Department of Health and Human Services that a March intrusion resulted in the theft of personal and health information belonging to more than 3.75 million people, ranking it as the fifth-largest health-data breach of 2026. The attackers exfiltrated data from the company's Amazon Web Services account, taking names, postal addresses, Social Security numbers, medical records, passports, driver’s licenses and banking details.
Based in New Jersey, CareCloud provides electronic medical-record storage for tens of thousands of U.S. healthcare providers, serving millions of patients. The company has not issued a public statement since the breach was first disclosed, and its chief executive Stephen Snyder has not answered media inquiries. This breach adds to a series of sizable health-data incidents this year, including a 3.4-million-record breach at TriZetto and an unspecified breach at Craneware, while DentaQuest leads the year’s tally with at least 15 million records compromised.
Why it matters
Millions of patients' sensitive health and financial data are exposed, raising privacy and security concerns nationwide.
In this story
