CareCloud Breach: 3.75 Million Patients' Medical Records Stolen

CareCloud has confirmed to federal regulators that hackers stole personal information and medical records belonging to more than 3.75 million people in a breach first disclosed in March 2026. The figure makes it the fifth-largest theft of health data reported so far this year. The New Jersey-based company, which provides electronic medical record storage to tens of thousands of healthcare providers across the United States, detailed the breach in a filing with the U.S. Department of Health and Human Services. The victim count was revised upward in an update on August 19, 2026. TechCrunch
The breach timeline spans several months. On March 16, 2026, CareCloud detected a network disruption affecting an electronic health record environment within its CareCloud Health division. According to the company's SEC filing, a hacker gained access to one of its six EHR environments for approximately eight hours. However, CareCloud later disclosed in data breach notifications that the attackers actually downloaded (or "exfiltrated") data from its Amazon Web Services account over a six-day window. The company filed a Current Report on Form 8-K with the U.S. Securities and Exchange Commission and, per The Record, informed the SEC that patients' electronic health records may have been leaked. HIPAA Journal
The scope of the stolen data is broad. According to CareCloud's breach notifications, the stolen information includes patients' names, postal addresses, Social Security numbers, medical and health information, government-issued identification numbers such as passports and driver's licenses, and banking and financial information. TechCrunch
The victim count has grown substantially since the breach was first reported. As of late July 2026, CareCloud had confirmed to state attorneys general that at least 345,000 individuals were affected, and the company began notifying patients around July 30, 2026. The August 19 update to HHS pushed that figure past 3.75 million, a more than tenfold increase. TechCrunch
CareCloud chief executive Stephen Snyder did not respond to multiple emails requesting information about the incident, including whether the company paid the hackers. TechCrunch
The CareCloud breach fits within a wider pattern of healthcare data compromises in 2026. According to HHS's running tally, dental insurance giant DentaQuest holds the largest breach reported this year, affecting at least 15 million people. TriZetto confirmed in March 2026 that a 2024 breach affected 3.4 million people's data. Craneware, a healthtech billing software maker, disclosed a July 2026 data breach affecting an as-yet-unspecified number of individuals. TechCrunch
The tenfold escalation in the victim count, from roughly 345,000 in late July to 3.75 million in mid-August, warrants attention. Such a revision suggests that the initial forensic assessment may have significantly underestimated the extent of data stolen from the AWS environment, or that the investigation later identified additional affected datasets within the compromised EHR system. For a company serving tens of thousands of healthcare providers, a breach of this scale means the downstream impact extends well beyond CareCloud itself to the individual practices and their patients who had no direct relationship with the vendor.
The data categories involved compound the risk. The combination of Social Security numbers, government-issued IDs, and financial information alongside medical records gives attackers a near-complete identity-theft package per affected individual. Medical records in particular carry long-lived sensitivity; unlike a compromised credit card number, a diagnosis or treatment history cannot be reissued or rotated.
Worth flagging is the gap between the eight-hour access window described in the SEC filing and the six-day exfiltration period cited in breach notifications. These figures may reflect different stages of the attack, with initial system access and the bulk data transfer occurring in separate timeframes, but the discrepancy raises questions about how quickly CareCloud detected and contained the theft from its AWS environment. The company's silence on whether a ransom was paid leaves an open question about how the incident was resolved, if it has been.
Healthcare has been a consistent target for data theft, and the 2026 breach landscape, with DentaQuest, TriZetto, Craneware, and now CareCloud, suggests the sector's security posture has not yet caught up with the value of the data it holds. For the EHR vendor ecosystem specifically, the incident is a reminder that cloud infrastructure, however well-provisioned, inherits risk from credential management, access controls, and monitoring gaps that are often the responsibility of the customer rather than the cloud provider.


