CareCloud confirms 3.7M patients had their medical records stolen in data breach

Get the Health newsletter
Daily health & science — research, biotech, public health, the studies worth knowing. Free.
- CareCloud confirmed in a Department of Health and Human Services filing that hackers stole the personal and medical records of more than 3.75 million people in a March data breach — now the fifth-largest health data theft of 2026, with the victim count reportedly revised upward in a Tuesday update.
- Hackers accessed patient data in one of CareCloud's cloud storage environments over six days and exfiltrated reams of data from the company's Amazon Web Services account, according to prior breach disclosures.
- The stolen records include patients' names, postal addresses, Social Security numbers, medical and health information, government-issued IDs (passports and driver's licenses), and banking and financial information.
- CareCloud CEO Stephen Snyder has not responded to multiple emails requesting information about whether the company paid the hackers, who handles cybersecurity at the firm, or whether he plans to resign following the incident.
- The breach follows other sizable 2026 healthcare attacks — TriZetto's March disclosure of a 2024 breach affecting 3.4 million people, a July breach at billing software maker Craneware, and DentaQuest's 15 million-affected incident, the largest of the year per HHS' running tally.
Why it matters: The breach exposes 3.75 million patients to identity theft and medical fraud risk, with Social Security numbers, government IDs, and bank details enabling long-term financial harm. CareCloud CEO Stephen Snyder's silence on whether ransom was paid — and on basic accountability questions like who runs cybersecurity — leaves millions of patients without answers about how their most sensitive data ended up in criminal hands.
Ask SkimNews




