THURSDAY, AUGUST 20, 2026
Published Daily in New York & Silicon Valley.
Latest News 19 AUGUST, 2026

CareCloud Confirms 3.7 Million Patients Had Their Medical Records Stolen in Data Breach

CareCloud confirms that over 3.75 million patients had their medical records stolen in a data breach, making it the fifth-largest theft of health data in 2026 so far.
NEWS DESK PUBLISHED: AUGUST 19, 2026
📖 3 MIN READ

CareCloud, a New Jersey-based tech company that provides electronic medical record storage to tens of thousands of healthcare providers across the United States, has confirmed that hackers stole the personal information and medical records of over 3.75 million people in a data breach. This disclosure marks the first confirmation of the scale of the data breach, which is now confirmed to be the fifth-largest theft of health data in 2026 so far.

In a filing with the Department of Health and Human Services (HHS) on Monday, CareCloud detailed the March data breach. The company initially reported that hackers had accessed patients’ medical data stored in one of its cloud storage environments over six days. However, the number of affected victims was reportedly revised up in an update on Tuesday, though it’s unclear if the figure is expected to rise further.

CareCloud handles a large amount of patient data and billing information on behalf of hospitals, doctor’s offices, and other medical practices. The company provides electronic medical record storage to healthcare providers across the United States, serving millions of patients. The stolen data includes patients’ names, postal addresses, Social Security numbers, and their medical and health information. The hackers also took government-issued identification numbers, such as passports and driver’s licenses, as well as banking and financial information.

CareCloud chief executive Stephen Snyder has not publicly commented on the cyberattack since it disclosed the breach in March. Despite multiple emails requesting information about the incident, including whether the company has paid the hackers, who is responsible for cybersecurity at the company, and if Snyder plans to resign following the incident, there has been no response.

The breach at CareCloud follows several sizable healthcare breaches confirmed this year. In March, tech giant TriZetto confirmed that a 2024 data breach affected 3.4 million people’s data. An as-yet-unspecified number of people have had their data stolen during a July data breach at healthtech billing software maker Craneware.

According to HHS’ running tally of healthcare data breaches, dental insurance giant DentaQuest has had the largest data breach this year so far, with at least 15 million people’s personal and health information being affected. The frequency and scale of these data breaches highlight the need for healthcare providers and technology companies to prioritize cybersecurity and protect sensitive patient information.

CareCloud’s data breach serves as a stark reminder of the importance of robust cybersecurity measures in the healthcare industry. As the company works to contain the fallout from this incident, it’s essential that healthcare providers and technology companies take a proactive approach to protecting patient data and preventing future breaches.

TravelSpots AI

Online Assistant

Hello! I am **TravelSpotsDaily**'s virtual assistant. Do you need any recommendations for travel destinations, food, or itineraries today? 😊
Explore Locations

Map & Regional Filter

Filter by Region