CareCloud Data Breach: 3.7 Million Patients' Medical Records Stolen
CareCloud confirms hackers stole the personal and medical records of 3.75 million patients in a March 2026 AWS breach. Here's what data was taken, who is affected, and what to do now.
Victor OgonyoHealth data management company CareCloud has confirmed one of the most significant medical data breaches of 2026: hackers stole the personal information and medical records of more than 3.75 million patients, the company disclosed to federal regulators this week.
The breach now ranks as the fifth-largest healthcare data theft of 2026 — and the full scale may still be growing.
What Happened
The cyberattack occurred in March 2026, when hackers gained unauthorized access to CareCloud's cloud infrastructure hosted on Amazon Web Services (AWS). According to the company's filing with the U.S. Department of Health and Human Services (HHS), attackers maintained access to the environment for six days before being detected — long enough to exfiltrate an enormous volume of sensitive patient data.
CareCloud first disclosed the breach in March but provided minimal details at the time. The company filed its confirmed victim count with HHS on Monday, and that figure was reportedly revised upward to 3.75 million on Tuesday, suggesting the full picture may still be incomplete.
What Data Was Stolen
The breach is notable not just for its scale but for the depth of information taken. According to CareCloud's breach notifications, stolen data includes:
- Full names and postal addresses
- Social Security numbers
- Medical and health records — diagnoses, treatments, prescriptions
- Government-issued ID numbers — passports and driver's licenses
- Banking and financial information
This combination of medical, financial, and identity data makes affected individuals highly vulnerable to identity theft, insurance fraud, and targeted phishing attacks. Medical identity theft in particular can take years to detect and can corrupt a patient's health records in ways that affect future care.
Who Is CareCloud?
CareCloud is a New Jersey-based health technology company that provides electronic health record (EHR) storage and medical billing services to tens of thousands of healthcare providers across the United States — including hospitals, private practices, and specialist clinics.
Because CareCloud sits in the middle of the healthcare data supply chain — handling records on behalf of providers rather than patients directly — a single breach of its systems cascades across a patient population that may have no awareness of or relationship with the company. Many of the 3.75 million affected patients likely have never heard of CareCloud.
CareCloud's Response — and the Silence From Leadership
Despite the confirmed scale of the breach, CareCloud's public communications have been minimal. CEO Stephen Snyder has not responded to repeated media inquiries, including questions about:
- Whether a ransom was paid to the attackers
- Who holds accountability for cybersecurity at the organization
- Whether Snyder plans to resign following the incident
The company has not held a press conference, issued a public statement, or updated its website with guidance for affected patients. Security researchers and patient advocates have criticized the lack of transparent communication, particularly given the sensitivity of the data involved and the breadth of the affected population.
2026's Healthcare Breach Problem
CareCloud's breach is part of a disturbing pattern in the healthcare sector this year:
| Company | Patients Affected | Notes |
|---|---|---|
| DentaQuest | 15M+ | Largest healthcare breach of 2026 so far |
| CareCloud | 3.75M | March 2026 AWS breach |
| TriZetto | 3.4M | 2024 breach, confirmed in March 2026 |
| Craneware | Undisclosed | July 2026 breach |
Healthcare remains the most targeted sector for data theft. Patient records command high prices on dark web marketplaces — typically far more than credit card data — because they contain everything an identity thief or fraudster needs in a single file.
What Affected Patients Should Do Right Now
If you've received a breach notification from CareCloud, or if you believe you may have been treated by a provider that uses CareCloud's platform, take these steps immediately:
1. Freeze your credit Place a credit freeze with all three major bureaus — Equifax, Experian, and TransUnion. It's free, it takes minutes online, and it prevents anyone from opening new credit accounts in your name.
2. Monitor your medical Explanation of Benefits (EOB) Watch your EOB statements for any claims you don't recognize. Medical identity theft — where criminals use stolen health data to bill insurers for fraudulent services — is one of the most damaging and hardest-to-reverse consequences of healthcare breaches.
3. Be alert to targeted phishing Criminals often use stolen health data to craft convincing, personalized scams. Be suspicious of any calls or emails claiming to be from your healthcare provider, insurance company, Medicare, or government agencies — especially if they ask for confirmation of personal details.
4. Use CareCloud's credit monitoring offer If you received a breach notification letter, it should include a code for free credit monitoring. Enroll as soon as possible.
5. Report suspicious activity Report identity theft to the FTC at IdentityTheft.gov or call 1-877-438-4338. File a police report if your identity has been actively misused.
The Regulatory and Industry Question
CareCloud's breach raises a question the healthcare industry has failed to adequately answer: why are EHR vendors — who hold data for millions of patients across thousands of providers — not held to the same cybersecurity standards as financial institutions?
HIPAA sets a minimum floor for healthcare data protection, but security researchers have long argued it is insufficient for cloud-scale infrastructure. With breaches of this size becoming routine, pressure is mounting on HHS and Congress to impose stricter cloud security mandates on healthcare data processors — companies that, by their position in the supply chain, create single points of catastrophic failure.
Bottom line: The CareCloud breach is a stark reminder that your medical records are only as secure as the least-secure vendor in your provider's technology stack. If you've received a breach notification — or even suspect you might be affected — act now. The window for getting ahead of identity theft closes quickly.
Building something great?
List your startup on Startup Launch Page -- reach real investors, founders, and early adopters.
Launch your startup →