Health tech company CareCloud has begun notifying approximately 345,000 people that hackers stole their medical records in a cyberattack that occurred in March 2026, with the total number of affected individuals expected to rise as additional state disclosures are filed.
According to a breach notice filed with California’s attorney general, hackers had access to one of CareCloud’s electronic health record data stores for at least six days, between March 10 and March 16. The company first disclosed the incident to regulators on March 27. The attacker “claimed to have exfiltrated data from databases,” a phrasing consistent with ransomware or extortion scenarios, though no group has publicly claimed responsibility for the attack.
The stolen data includes names, postal addresses, Social Security numbers, government-issued identification numbers such as passports and driver’s licenses, bank account information, payment card numbers, and a range of medical and health-related information. The breached data store was hosted on Amazon Web Services.
New Jersey-based CareCloud stores patient records for more than 45,000 healthcare providers across the U.S., including doctors’ offices and hospitals, handling sensitive medical and billing data for millions of patients nationwide. Affected individuals have been identified through filings with attorneys general in California, New Hampshire, Massachusetts, Texas, and Maine.
CareCloud CEO Stephen Snyder did not respond to requests for comment. The company has provided limited public detail about the breach beyond its initial March disclosure.
The incident is one of several large-scale healthcare data breaches reported in 2026. Others include a breach at TriZetto affecting 3.4 million people, a month-long intrusion at NYC Health + Hospitals in which hackers stole 1.8 million people’s health data, and a recently confirmed breach at U.K.-based healthcare billing software provider Craneware involving a “significant volume” of customer data.
Source: TechCrunch