CareCloud Confirms Massive Healthcare Data Breach Affecting 3.75 Million Patients
CareCloud, a New Jersey-based provider of electronic health record (EHR) storage and payment processing services, has reported one of the largest healthcare data breaches in the U.S. this year. The incident, which occurred in March, exposed the personal and medical information of over 3.75 million patients, ranking it as the fifth-largest healthcare breach since the start of 2026.
The company disclosed the attack to the U.S. Department of Health and Human Services (HHS) on August 17, later revising the number of affected individuals upward. Hackers gained access to a CareCloud cloud environment hosted on Amazon Web Services for six days, during which they exfiltrated sensitive data. Compromised information may have included names, mailing addresses, Social Security numbers, medical records, government-issued IDs (such as passport and driver’s license numbers), and financial details.
CareCloud has not provided further details on the attack, including whether a ransom was paid, who oversees its cybersecurity operations, or whether leadership changes are planned. CEO Stephen Snyder has not responded to repeated inquiries.
The breach comes amid a surge in cyberattacks targeting U.S. healthcare organizations. In March, TriZetto confirmed a 2024 incident affecting 3.4 million individuals, while Craneware, a medical billing software provider, reported a July breach with an undetermined number of victims. The largest confirmed healthcare breach of 2026 remains a DentaQuest incident, potentially impacting 15 million people.
The CareCloud attack underscores the growing risks to healthcare providers and patients as threat actors increasingly target cloud-stored sensitive data.
Source: https://mezha.net/eng/bukvy/83ce1e12_carecloud_reports_medical/
CareCloud cybersecurity rating report: https://www.rankiteo.com/company/carecloud
TriZetto Healthcare Products cybersecurity rating report: https://www.rankiteo.com/company/trizetto-healthcare-products
"id": "CARTRI1787150196",
"linkid": "carecloud, trizetto-healthcare-products",
"type": "Breach",
"date": "3/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '3.75 million patients',
'industry': 'Healthcare',
'location': 'New Jersey, USA',
'name': 'CareCloud',
'type': 'Healthcare Service Provider'}],
'attack_vector': 'Cloud Environment Compromise',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '3.75 million',
'personally_identifiable_information': 'Names, mailing '
'addresses, Social '
'Security numbers, '
'passport and driver’s '
'license numbers',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personal Information',
'Medical Records',
'Government-Issued IDs',
'Financial Details']},
'date_detected': '2026-03',
'date_publicly_disclosed': '2026-08-17',
'description': 'CareCloud, a New Jersey-based provider of electronic health '
'record (EHR) storage and payment processing services, '
'reported a massive healthcare data breach affecting 3.75 '
'million patients. Hackers gained access to a CareCloud cloud '
'environment hosted on Amazon Web Services for six days, '
'exfiltrating sensitive data including personal and medical '
'information.',
'impact': {'brand_reputation_impact': 'High',
'data_compromised': 'Personal and medical information of 3.75 '
'million patients',
'identity_theft_risk': 'High',
'payment_information_risk': 'High',
'systems_affected': 'CareCloud cloud environment (Amazon Web '
'Services)'},
'ransomware': {'data_exfiltration': 'Yes'},
'references': [{'source': 'U.S. Department of Health and Human Services '
'(HHS)'}],
'regulatory_compliance': {'regulations_violated': ['HIPAA'],
'regulatory_notifications': 'Reported to U.S. '
'Department of Health '
'and Human Services '
'(HHS)'},
'title': 'CareCloud Healthcare Data Breach',
'type': 'Data Breach'}