CareCloud confirms 3.7M patients had their medical records stolen in data breach
The cyberattack at CareCloud resulted in one of the largest reported data breaches in the U.S. healthcare industry this year.
A data breach at health data company CareCloud has exposed the personal information and medical records of over 3.75 million individuals, marking the fifth-largest theft of health data in 2026 thus far. The breach, which was first disclosed in March, was confirmed with federal regulators in an update on Tuesday, raising the total number of affected victims.
CareCloud, based in New Jersey, offers electronic medical record storage services to thousands of healthcare providers across the United States, handling millions of patient data and billing information for hospitals, doctor's offices, and other medical practices.
The stolen data includes patients' names, postal addresses, Social Security numbers, and their medical and health information. Additionally, hackers obtained government-issued identification numbers, such as passports and driver's licenses, as well as banking and financial information. CareCloud's chief executive Stephen Snyder has not responded to inquiries regarding the incident, including whether the company has paid the hackers or plans to resign.
The breach follows several other significant healthcare breaches this year, including a 2024 data breach at TriZetto affecting 3.4 million people's data and an unspecified number stolen during a July breach at health tech billing software maker Craneware. As of now, DentaQuest, a dental insurance giant, has the largest healthcare data breach reported so far, with at least 15 million people's personal and health information compromised.
Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.