Hackers have stolen the personal and medical records of over 3.75 million people following a data breach at healthcare giant CareCloud, according to federal regulators.
The incident marks the fifth-largest theft of health data in 2026 so far, as CareCloud detailed in a filing with the Department of Health and Human Services (HHS). The number of affected victims has been revised upwards since March, indicating further exposure could be possible.
CareCloud provides electronic medical record storage services to thousands of healthcare providers across the United States. Security concerns have risen following this breach, given the sensitive nature of the data stored, including names, addresses, Social Security numbers and financial information.
The company’s CEO, Stephen Snyder, has not publicly addressed the incident since its initial disclosure in March, raising questions about his response to such a major cyber-attack. CareCloud has yet to confirm whether it paid any ransom or if there are measures being taken to prevent future breaches.
This breach comes amid other significant healthcare data breaches this year, highlighting ongoing concerns over cybersecurity within the industry and the potential for personal and medical information to fall into the wrong hands.







