CareCloud Confirms 3.75M Patient Records Stolen In March Breach

CareCloud filed with HHS on August 19, 2026 confirming hackers stole personal, financial and medical records of 3.75 million patients when attackers accessed one of the EHR provider's AWS environments in March.

CareCloud Confirms 3.75M Patient Records Stolen In March Breach

Health data giant CareCloud confirmed on August 19, 2026 that hackers stole the personal information and medical records of more than 3.75 million people during a March 2026 breach of its Amazon Web Services (AWS) environment, marking one of the five largest U.S. healthcare data thefts of the year.

What was taken

The Somerset, New Jersey-based company (Nasdaq: CCLD) told the U.S. Department of Health and Human Services that stolen data includes patient names, postal addresses, Social Security numbers, government-issued identification such as passports and driver's licenses, medical and health information, insurance details and banking or financial data. The number of affected individuals was reportedly revised upward from an initial 3.4 million on August 20, and the figure may still climb.

How the attack unfolded

CareCloud first disclosed the intrusion in March 2026, saying hackers had accessed patient medical data stored in one of its cloud environments over roughly six days between March 10 and March 16. In July, the company began mailing individual breach notifications, at which point it acknowledged that attackers exfiltrated data from its AWS account. Chief executive Stephen Snyder has not publicly commented on the incident since the original March disclosure, and the company has not said whether any ransom was paid.

CareCloud EHR platform used by more than 45,000 U.S. healthcare providers.

Where it fits in a bad year for health data

The confirmation lands during a punishing 2026 for healthcare cybersecurity. Dental insurance giant DentaQuest tops HHS's running tally so far with at least 15 million records exposed, tech giant TriZetto confirmed a 3.4 million person breach dating to 2024, and health billing software maker Craneware disclosed a July breach whose scope has not yet been detailed. The healthcare-tech sector has also been hit by the ShinyHunters campaign against McKesson, adding to pressure on cyber underwriters and boards. Investors will now watch whether CareCloud's next 10-Q quantifies the material impact and whether the U.S. Federal Trade Commission or state attorneys general open enforcement actions.

What CareCloud provides

CareCloud is a publicly traded software-as-a-service platform serving more than 45,000 healthcare providers and 150 hospitals across the United States. Its products span electronic health records, revenue cycle management, practice management, telehealth and, more recently, generative-AI clinical documentation tools such as its cirrusAI suite and stratusAI Desk Agent virtual receptionist. Coverage of adjacent healthcare-cyber incidents is available in our reports on the Manchester Airports Group breach and Berlin's refusal to pay Rhysida ransomware.

Reporting based on coverage from TechCrunch, SecurityWeek, HIPAA Journal and CareCloud's HHS filing.

Category: Cyber Security

Tags: Healthcare Technology Cybersecurity Partnership Data Breach

Related Articles