
The CEO hasn’t responded to press emails. The company has made no public statement. And yet, somewhere out there, 3.75 million people’s Social Security numbers, medical histories, and banking details are in the hands of hackers. That’s the situation at CareCloud, a New Jersey-based health tech company that has now been confirmed, according to TechCrunch, as the source of the fifth-largest healthcare data breach of 2026.
CareCloud filed details of the March breach with the Department of Health and Human Services on Monday. The victim count was revised upward on Tuesday, and it’s not clear whether it will climb further. These kinds of upward revisions are common in large breaches, and they rarely stop at the first number.
The company provides electronic medical record storage to tens of thousands of healthcare providers across the United States. That means it sits on an enormous pile of patient data, billing records, and sensitive health information, not just for one hospital or clinic, but for a wide network of practices. When a company like this gets hit, the damage doesn’t stay contained. It spreads across every provider that trusted the platform with their patients’ data.
What was stolen is about as bad as it gets. The list includes:
- Full names and postal addresses
- Social Security numbers
- Medical and health records
- Government-issued ID numbers, including passports and driver’s licenses
- Banking and financial information
The hackers accessed CareCloud’s Amazon Web Services account and pulled data over a six-day window before anyone apparently noticed. That’s six days of undetected access to one of the most sensitive categories of personal data that exists. Medical records don’t expire. You can’t change your health history the way you can change a password.
CareCloud CEO Stephen Snyder has not responded to press questions, including whether the company paid a ransom or who is responsible for its cybersecurity. That silence is a choice, and it’s one that leaves millions of affected patients with almost no information about what comes next for them.
This breach doesn’t exist in isolation. Healthcare has become one of the most targeted sectors for data theft. TriZetto confirmed in March that a 2024 breach affected 3.4 million people. Craneware reported a July breach with no victim count yet. And dental insurer DentaQuest holds the grim top spot this year, with at least 15 million people’s data compromised. The pattern is consistent: large aggregators of health data, minimal public accountability, and patients left to absorb the consequences.
The industry’s response to these incidents is still nowhere near where it needs to be. And until regulators start demanding real answers, companies like CareCloud will keep going quiet and hoping the news cycle moves on.