Hackers Stole Medical Records From 3.75 Million People. Here's What Happened.

CareCloud, a company that stores electronic medical records for thousands of doctors and hospitals across the United States, has confirmed that hackers stole personal information and medical records belonging to more than 3.75 million people. The breach was first disclosed in March 2026, and the number of victims was raised in an update on August 19, 2026. It is the fifth-largest theft of health data reported so far this year. The New Jersey-based company detailed the breach in a filing with the U.S. Department of Health and Human Services. TechCrunch
The breach played out over several months. On March 16, 2026, CareCloud noticed a problem with one of its systems that stores electronic health records. According to a filing with the Securities and Exchange Commission, a hacker had access to one of the company's six record systems for about eight hours. But CareCloud later said in breach notifications that the attackers actually downloaded data from its Amazon Web Services account over a six-day period. Amazon Web Services is a cloud computing platform where CareCloud stored its data. HIPAA Journal
The stolen information is extensive. According to CareCloud's breach notifications, it includes patients' names, home addresses, Social Security numbers, medical and health information, government-issued ID numbers such as passports and driver's licenses, and banking and financial information. TechCrunch
The number of people affected has grown a great deal since the breach was first reported. As of late July 2026, CareCloud had told state attorneys general that at least 345,000 individuals were affected, and the company began notifying patients around July 30, 2026. The August 19 update to HHS pushed that figure past 3.75 million, more than ten times the earlier number. TechCrunch
CareCloud chief executive Stephen Snyder did not respond to multiple emails requesting information about the incident, including whether the company paid the hackers. TechCrunch
The CareCloud breach is part of a wider pattern of healthcare data theft in 2026. According to HHS's running tally, dental insurance company DentaQuest reported the largest breach this year, affecting at least 15 million people. TriZetto confirmed in March 2026 that a 2024 breach affected 3.4 million people's data. Craneware, a company that makes billing software for healthcare, disclosed a July 2026 data breach affecting an as-yet-unspecified number of individuals. TechCrunch
The jump from 345,000 victims in late July to 3.75 million in mid-August deserves attention. It suggests that the company's first investigation may have seriously underestimated how much data was taken, or that investigators later found additional affected files. Because CareCloud serves tens of thousands of healthcare providers, the impact reaches well beyond the company itself to individual doctor's offices and patients who had never heard of CareCloud.
The types of data stolen make the situation worse. Social Security numbers, government IDs, and financial details combined with medical records give attackers nearly everything they need to steal someone's identity. Medical records are especially sensitive because, unlike a credit card number that can be cancelled and reissued, a diagnosis or treatment history cannot be changed.
There is also a gap worth noting between the company's statements. CareCloud told the SEC the hacker had access for about eight hours, but its breach notifications say data was downloaded over six days. These could represent different stages of the attack, but the discrepancy raises questions about how quickly CareCloud noticed and stopped the theft. The company has not said whether it paid a ransom, leaving it unclear how the incident was resolved.
Healthcare has long been a target for data theft, and the 2026 breaches at DentaQuest, TriZetto, Craneware, and now CareCloud suggest the industry's security has not caught up with how valuable its data is. For companies that store medical records in the cloud, this incident is a reminder that even well-built cloud systems carry risks from weak passwords, poor access controls, and gaps in monitoring that are typically the customer's responsibility, not the cloud provider's.


