More than 3.75 million people had their personal and medical information stolen in a data breach at health data firm CareCloud, the company confirmed in a filing with the Department of Health and Human Services on Monday. The disclosure is the first official confirmation of the scale of the incident, which the company initially reported in March. According to the federal filing, the breach now ranks as the fifth-largest theft of health data in the United States in 2026 so far, though CareCloud revised the victim count upward in a separate update on Tuesday.
CareCloud, based in New Jersey, provides electronic medical record storage to tens of thousands of healthcare providers across the country, serving millions of patients. The company manages patient data and billing information on behalf of hospitals, doctor’s offices, and other medical practices. The cyberattack involved unauthorized access to patient medical data stored in one of the company’s cloud storage environments over a six-day period, according to the company’s initial March disclosure. Later data breach notifications said the hackers exfiltrated data from CareCloud’s Amazon Web Services account.
The stolen information includes patients’ names, postal addresses, Social Security numbers, and medical and health records. The hackers also obtained government-issued identification numbers, such as passports and driver’s licenses, as well as banking and financial details. CareCloud has not publicly commented on the attack beyond its earlier statements, and chief executive Stephen Snyder has not responded to multiple email requests for information about the incident. Those unanswered questions include whether the company paid the hackers, who is responsible for cybersecurity at the firm, and whether Snyder plans to resign.
The CareCloud breach adds to a series of large healthcare data incidents confirmed this year in the United States. Tech company TriZetto confirmed in March that a 2024 breach affected 3.4 million people’s data. Healthtech billing software maker Craneware also reported a July data breach, though the number of affected individuals has not been specified.
According to the Department of Health and Human Services’ running tally of healthcare data breaches, dental insurance giant DentaQuest has seen the largest incident this year so far, affecting at least 15 million people’s personal and health information. The CareCloud figure places it behind DentaQuest and several other major incidents in the national ranking. Federal regulators have not indicated whether the CareCloud count is expected to rise further.








