IT-PUB NEWS

CareCloud says 3.75 million patients were affected

20.08.2026 15:03 • Author: IT-PUB
CareCloud says 3.75 million patients were affected

A revised filing says the March breach exposed medical, identity, and financial data, pushing the incident among the biggest healthcare thefts reported this year.

CareCloud has confirmed that hackers stole the personal and medical information of more than 3.75 million people in a breach tied to the company’s health data systems. The disclosure, filed with federal regulators, is the first official confirmation of the breach’s scale and puts it among the biggest healthcare data thefts reported this year. CareCloud stores electronic medical records for tens of thousands of healthcare providers across the United States, so the effects reach far beyond a single company. For patients, the concern is straightforward: once this kind of data is exposed, it can be extremely hard to secure again.

CareCloud raised its count of affected patients

CareCloud described the March incident in a filing with the Department of Health and Human Services on Monday. On Tuesday, the number of affected people was revised upward, though it remains unclear whether the total could increase again.

The New Jersey-based company has not publicly commented on the cyberattack since first disclosing the breach in March. At the time, CareCloud said hackers had accessed patient medical data stored in one of its cloud environments over a six-day period.

Later breach notifications said the attackers exfiltrated data from CareCloud’s Amazon Web Services account and took large amounts of patient information. That account appears to have been one of the main targets in the intrusion, according to the company’s own notices, as IT-PUB News reports.

Names, Social Security numbers, and medical data were taken

The stolen information went well beyond basic contact details. According to the filing and breach notifications, the attackers took patients’ names, postal addresses, Social Security numbers, medical and health information, government-issued identification numbers such as passports and driver’s licenses, and banking and financial information.

That combination raises the stakes for affected patients. Medical information can be misused in ways that are harder to spot than a stolen password, while identity documents and financial details can create additional risks when used together. This is not just a privacy issue — it also touches personal security.

CareCloud handles patient data and billing information for hospitals, doctor’s offices, and other medical practices. Because of that role, one compromise can spread across multiple healthcare organizations and the patients they serve.

CareCloud still has not answered key questions

CareCloud chief executive Stephen Snyder has not responded to multiple emails seeking details about the incident. Among the unanswered questions are whether the company paid the hackers, who is responsible for cybersecurity at the company, and whether Snyder plans to resign after the breach.

That silence has kept scrutiny on the case. CareCloud has now confirmed the scale of the incident, but it still has not publicly explained in detail how the breach happened or how it is dealing with the fallout.

For patients, the uncertainty is practical as much as reputational. People affected by a breach like this usually want to know not only what was taken, but also what protections are now in place and whether the company has the internal oversight needed to prevent a repeat.

CareCloud joins a growing list of major healthcare breaches

The CareCloud case comes amid several other major healthcare breaches confirmed this year. In March, TriZetto said a 2024 breach affected 3.4 million people. In July, Craneware reported a data theft involving an unspecified number of people.

The Department of Health and Human Services’ running tally of healthcare data breaches shows that DentaQuest has had the largest breach so far this year, with at least 15 million people’s personal and health information affected.

Against that backdrop, CareCloud’s breach now ranks as the fifth-largest theft of health data in 2026 so far. The size matters, but so does the mix of information taken. When medical records, identity documents, and financial details are exposed together, the damage can extend well beyond a company’s systems and into patients’ daily lives.


Improve SEO for a small/medium business website for $50