Health data company CareCloud has confirmed that hackers stole the personal information and medical records of more than 3.75 million people in a breach first disclosed in March 2026, making it the fifth-largest theft of health data in the U.S. this year.
CareCloud detailed the breach in a filing with the Department of Health and Human Services on Monday, August 18, 2026, with the number of affected individuals revised upward in an update the following day. It remains unclear whether the figure will rise further.
The New Jersey-based company provides electronic medical record storage to tens of thousands of healthcare providers across the United States, serving millions of patients on behalf of hospitals, doctor’s offices, and other medical practices. According to the company’s earlier breach notifications, hackers accessed patient data stored in one of CareCloud’s cloud storage environments over six days and exfiltrated data from the company’s Amazon Web Services account.
The stolen data includes patients’ names, postal addresses, Social Security numbers, medical and health information, government-issued identification numbers such as passports and driver’s licenses, and banking and financial information.
CareCloud CEO Stephen Snyder has not responded to requests for comment on the incident, including questions about whether the company paid the hackers, who oversees cybersecurity at the company, or whether Snyder intends to resign.
The breach is among several large healthcare data incidents confirmed in 2026. Tech giant TriZetto confirmed in March that a 2024 breach affected 3.4 million people, and healthtech billing software maker Craneware disclosed a July breach affecting an unspecified number of individuals. The largest U.S. healthcare breach this year remains dental insurance giant DentaQuest, with at least 15 million people’s personal and health information affected, according to HHS data.
The scale of the CareCloud breach may expose millions of patients to identity theft and financial fraud risks, given the breadth of sensitive data stolen.
Source: TechCrunch