CareCloud has confirmed that the March 2026 intrusion into its Amazon Web Services environment exposed the data of 3,756,469 individuals — more than ten times the figure it disclosed when notifications began.
The revised count was posted to the HHS Office for Civil Rights breach portal this week. When we covered the first wave of notices on August 3, the confirmed total stood at at least 345,000 people, including 270,197 Texas residents reported to that state’s attorney general. That number was never the ceiling. It was the portion of the victim set CareCloud had finished identifying.
The final tally makes this the fifth-largest theft of health data recorded in 2026.
The Timeline Has Not Changed. Only the Number Has.
- March 10–16, 2026 — an unauthorized third party accesses one of CareCloud’s AWS environments
- March 16, 2026 — network disruption detected; the environment is restored the same evening
- March 24, 2026 — CareCloud determines the incident is material
- March 30, 2026 — the company files a Form 8-K with the SEC
- June 24, 2026 — CareCloud confirms which data types were involved
- August 3, 2026 — first patient notifications go out by mail
- August 18–19, 2026 — the breach is posted to the HHS OCR portal, then revised to 3,756,469
Six days of access. Five months to the first letter. Five months and change to the accurate count.
The gap between March 16 and June 24 is the part worth sitting with. CareCloud knew on March 24 that the incident was material enough to require an SEC filing — a determination made for investors within eight days. It took another three months to determine what had been taken from patients, and another six weeks after that to tell them.
What Was Taken
The exposed data set is close to the maximum a healthcare technology vendor can hold:
- Names, addresses, dates of birth
- Social Security numbers
- Driver’s license and government-issued ID numbers
- Financial account numbers
- Credit and debit card numbers
- Medical and health insurance information
That is the identity-theft package, the payment-fraud package, and the medical-records package in one breach. CareCloud’s position in the healthcare stack is why: the Somerset, New Jersey company sells electronic health records, medical billing, practice management and revenue-cycle services to tens of thousands of healthcare providers. A practice that consolidates its records, its documentation and its collections onto one platform hands all three categories of patient data to one set of credentials.
Nobody Has Claimed It
Five months on, no ransomware group has listed CareCloud on a leak site. No extortion post, no countdown timer, no sample dump.
The company has said an unauthorized party “claimed to have exfiltrated data” from databases in the compromised AWS environment — language that implies direct contact between the attacker and the victim. Direct contact plus prolonged silence on the leak sites is the signature pattern of a negotiated resolution. CareCloud has not disclosed whether a payment was made, and CEO Stephen Snyder has not commented publicly since the March disclosure.
Silence is not proof of payment. But in an extortion economy where publication is the entire leverage mechanism, a haul of 3.7 million records with SSNs and payment cards does not sit unpublished for five months by accident.
The Pattern Nobody Is Fixing
CareCloud joins a run of 2026 healthcare breaches where the damage came through a vendor rather than a hospital:
- TriZetto Provider Solutions — 3,433,965 individuals, reported February
- Craneware — a revenue-cycle vendor reaching roughly 2,000 hospitals, disclosed July
- DentaQuest — a benefits administrator hit by ShinyHunters
- Conduent — 62,224,658 people, the third-largest healthcare breach in U.S. history
None of these organizations treat patients. All of them hold patient data at a scale no individual provider does. The patients whose records were stolen from CareCloud have, in nearly every case, never heard the company’s name.
The initial-count-versus-final-count gap is its own recurring failure. Conduent opened at 10.5 million and closed at 62.2 million. CareCloud opened at 345,000 and closed at 3.76 million. Both counts were technically accurate when filed and both were useless as a measure of the event. Anyone reading the first disclosure of a large vendor breach and treating the number as the scale of the incident is reading a progress report, not a finding.
What Affected Patients Should Do
Because Social Security numbers and government IDs are in the set, the standard credit-monitoring response is insufficient on its own:
- Freeze credit at Equifax, Experian and TransUnion — free, and more effective than monitoring
- Replace exposed payment cards rather than waiting for fraud alerts
- Request an IRS Identity Protection PIN — SSNs in a breach set of this size feed tax-refund fraud
- Review Explanation of Benefits statements for care you did not receive; medical identity theft surfaces there first
- Treat unsolicited “CareCloud” outreach as fraud — breach victim lists are themselves resold to phishing operators
Sources
- TechCrunch: CareCloud confirms 3.7M patients had their medical records stolen in data breach
- HIPAA Journal: CareCloud Data Breach Affects 3.75 Million Individuals
- The Record: Electronic health record company CareCloud says 3.7 million people affected by breach
- BleepingComputer: Healthtech firm CareCloud data breach impacts 3.7 million patients



