Hackers Stole Medical Records and Personal Details from 345,000 People

CareCloud, a New Jersey company that stores medical records for doctors and hospitals, has started notifying hundreds of thousands of people that hackers stole their personal and medical information earlier this year. The breach affects at least 345,000 people across the United States, according to filings with the attorneys general of New Hampshire, Massachusetts, Texas, and Maine (TechCrunch).
Hackers had access to CareCloud's systems for six days, from March 10 to March 16, 2026. The company told the U.S. Securities and Exchange Commission about the breach in a filing dated March 27, 2026 (SEC Filing). TechCrunch first reported the story on March 31, 2026.
CareCloud filed a formal breach notice with the California Attorney General's office in the week of July 30, 2026. California's data breach portal lists the breach date as March 10, 2026 and the report date as July 25, 2026 (California AG Portal). A hacker claimed to have copied data from CareCloud's databases. The stolen information is extensive: names, addresses, Social Security numbers, passport numbers, driver's license numbers, bank account and payment card numbers, and medical and health information.
As of July 30, 2026, no hacking group had publicly claimed responsibility for the breach. CareCloud CEO Stephen Snyder did not respond to TechCrunch's request for comment. CareCloud stores patient records for more than 45,000 healthcare providers across the U.S., including doctors' offices, hospitals, and other medical practices.
The gap between the company's March disclosure to federal regulators and its July notifications to affected individuals fits within the rules set by HIPAA, the federal health privacy law. HIPAA gives companies up to 60 days from the time they discover a breach to notify the people affected. The California filing on July 25 falls within that window, but it raises questions about when CareCloud started the clock — whether from the date it first noticed unauthorized access, or from when it confirmed data had actually been stolen.
The types of data stolen here give criminals nearly everything they would need to steal someone's identity. Social Security numbers, bank account details, and government ID numbers, combined with medical information, could be used to open fraudulent accounts, file fake insurance claims, or commit financial fraud. Medical data is especially valuable to criminals because, unlike a credit card, it cannot be canceled and reissued.
CareCloud keeps its patient data in six separate storage systems, and only one was breached. That separation may have limited the damage. The breached system was hosted on Amazon's cloud service, which means the hackers likely got in by stealing login credentials, exploiting misconfigured settings, or finding a weakness in how the system's access tools worked — rather than breaking into CareCloud's own corporate network. No ransomware group has claimed responsibility, which suggests the hackers may plan to sell the stolen data rather than demand a ransom.
For the 45,000-plus doctors and hospitals that rely on CareCloud, the impact is significant. Patients whose data was stolen face personal risk, and the providers themselves face compliance and reputational damage.
In this author's view, this incident highlights a deeper problem in healthcare technology. When patient records from tens of thousands of practices are centralized through a small number of shared platforms, it makes things more efficient — but it also means that a single breach can affect a huge number of people across many different providers.
CareCloud has not publicly explained exactly how the hackers got in, what steps the company has taken since March to fix the problem, or whether it checked its other five data storage systems for signs of compromise. The company's SEC filing confirmed that unauthorized access occurred, but the full picture may not emerge until additional state filings or regulatory actions come to light.


