Cybersecurity

CareCloud breach affects 345,000 as hackers steal medical records

1 min read

CareCloud breach affects 345,000 as hackers steal medical records
Photo: Juanjo Jaramillo · Unsplash
0 0
XWhatsAppTelegramLinkedIn

The New Jersey-based health technology company CareCloud, which stores patient records for over 45,000 providers, has started notifying at least 345,000 individuals that their medical records and Social Security numbers were stolen in a March 2026 cyberattack. Hackers accessed one of its electronic health record data stores on Amazon Web Services for six days, from March 10 to 16, 2026, stealing names, addresses, government-issued IDs, bank account details, payment card numbers and detailed health information.

CareCloud disclosed the breach to regulators on March 27, 2026, but provided few details until a filing with California’s attorney general on July 28, 2026, revealed the scope.

A hacker ‘claimed to have exfiltrated data from databases,’ the filing stated, but CareCloud did not explain how it received the claim.

State disclosures, filed with attorneys general in New Hampshire, Massachusetts, Texas, Maine and California, indicate that the total number of affected individuals is likely to rise as more notifications are filed. CareCloud chief executive Stephen Snyder did not respond to a request for comment.

The incident adds to a wave of 2026 healthcare breaches. TriZetto had data on 3.4 million people compromised; a month-long intrusion at NYC Health + Hospitals exposed health data of 1.8 million patients and fingerprint scans of thousands of employees; and U.K. vendor Craneware confirmed hackers stole a ‘significant volume’ of customer data from its servers.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.