CareCloud has officially confirmed that a security breach impacting its systems resulted in the theft of medical and personal records for over 3.7 million patients. The company disclosed the incident in a filing with the Department of Health and Human Services, marking the event as the fifth-largest health data theft of 2026. This breach involved unauthorized access to a cloud storage environment hosted on Amazon Web Services where the company keeps patient data for various healthcare providers.
The compromised information includes sensitive identifiers such as Social Security numbers, passport details, driver’s licenses, and banking information. In addition to these financial records, the attackers obtained medical history and contact details. CareCloud provides electronic record storage and billing services to numerous medical practices across the United States, which accounts for the vast scale of the exposed data.
While the breach occurred in March, the company only recently finalized the total count of affected individuals. CareCloud has remained largely silent regarding the specific circumstances of the attack. CEO Stephen Snyder has not addressed inquiries concerning whether a ransom was paid or the status of internal security leadership.
This incident sits among a series of major security failures within the healthcare sector throughout 2026. Other organizations including TriZetto and Craneware reported significant data thefts earlier this year, while DentaQuest recorded the largest breach of 2026 with 15 million individuals affected. These repeated events draw attention to the security posture of companies that act as central hubs for medical record storage.

