← Back to Issue

CareCloud confirms 3.7M patients had their medical records stolen in data breach

From aiste.ulozaite@gmail.com · original ↗ · unsubscribe

The cyberattack at CareCloud resulted in one of the largest reported data breaches in the U.S. healthcare industry this year.


CareCloud confirms 3.7M patients had their medical records stolen in data breach TechCrunch

–:–:–:–

🚨 Flash Sale 🚨 Get $100 off your Disrupt 2026 ticket

Save $300 on your Disrupt 2026 ticket: REGISTER NOW.

Close

TechCrunch Desktop Logo

TechCrunch Mobile Logo

Search

Submit

Site Search Toggle

Mega Menu Toggle

Topics

Latest

AI

Amazon

Apps

Biotech & Health

Climate

Cloud Computing

Commerce

Crypto

Enterprise

EVs

Fintech

Fundraising

Gadgets

Gaming

Google

Government & Policy

Hardware

Instagram

Layoffs

Media & Entertainment

Meta

Microsoft

Privacy

Robotics

Security

Social

Space

Startups

TikTok

Transportation

Venture

More from TechCrunch

Staff

Events

Startup Battlefield

StrictlyVC

Newsletters

Podcasts

Videos

Partner Content

TechCrunch Brand Studio

Contact Us

hacking surveillance image

Image Credits:Bryce Durbin / TechCrunch

Security

CareCloud confirms 3.7M patients had their medical records stolen in data breach

Zack Whittaker

6:04 AM PDT · August 19, 2026

Hackers have stolen the personal information and medical records of more than 3.75 million people in a data breach at health data giant CareCloud, the company has confirmed with federal regulators. The disclosure marks the first confirmation of the scale of the data breach, which is now confirmed to be the fifth-largest theft of health data in 2026 so far.

CareCloud detailed the March data breach in a filing with the Department of Health and Human Services (HHS) on Monday. The number of affected victims was reportedly revised up in an update on Tuesday, though it’s unclear if the figure is expected to rise further.

The New Jersey-based tech company provides electronic medical record storage to tens of thousands of healthcare providers around the United States, consequently serving millions of patients. CareCloud handles a large amount of patient data and billing information on behalf of hospitals, doctor’s offices, and other medical practices.

CareCloud has not publicly commented on the cyberattack since it disclosed the breach in March, when it said hackers had accessed patients’ medical data stored in one of its cloud storage environments over six days. The company later said in data breach notifications that the hackers exfiltrated data from the company’s Amazon Web Services account and stole reams of patient data.

The stolen data includes patients’ names, postal addresses, Social Security numbers, and their medical and health information. The hackers also took government-issued identification numbers, such as passports and driver’s licenses, as well as banking and financial information.

CareCloud chief executive Stephen Snyder has not responded to multiple emails requesting information about the incident, including whether the company has paid the hackers; who, if anyone, is responsible for cybersecurity at the company; or if Snyder plans to resign following the incident.

The breach at CareCloud follows several sizable healthcare breaches confirmed this year.

Tech giant TriZetto confirmed in March that a 2024 data breach affected 3.4 million people’s data, and an as-yet-unspecified number of people had their data stolen during a July data breach at health tech billing software maker Craneware.

According to HHS’ running tally of healthcare data breaches, dental insurance giant DentaQuest has had the largest data breach this year so far, with at least 15 million people’s personal and health information being affected.

Topics

Amazon Web Services, carecloud, cyberattack, data breach, electronic health records, healthcare, Security

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Zack Whittaker

Zack Whittaker

Security Editor

Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.

He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.

View Bio

Event Logo

October 13 – 15

San Francisco

In less than 48 hours, your chance to save up to $300 on your tickets will end!

REGISTER NOW

Loading the next article

Error loading the next article

TechCrunch Logo

© 2026 TechCrunch Media LLC.

Highlights & notes

    Notes