READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

CareCloud Tells 345,000 People Their Medical and Financial Records Were Stolen in March Hack

CareCloud Tells 345,000 People Their Medical and Financial Records Were Stolen in March Hack
CareCloud is notifying roughly 345,000 people that hackers accessed their medical records, Social Security numbers, and financial data during a six-day breach in March. The health tech company waited months to detail what was taken, and the number of victims is expected to climb as more states report in.

CareCloud, a New Jersey-based health tech company that stores patient records for more than 45,000 medical providers nationwide, is sending breach notification letters to hundreds of thousands of people whose data was stolen by hackers earlier this year, according to TechCrunch.

The company first disclosed the breach to regulators on March 27, admitting hackers had broken into one of its six patient data stores. But CareCloud said little publicly for months. New filings with state attorneys general, reviewed by TechCrunch, now show the hackers had access to the compromised database for at least six days, from March 10 to March 16.

At least 345,000 people are confirmed affected so far, based on breach notices filed in New Hampshire, Massachusetts, Texas, and Maine, TechCrunch reported. That number is likely to grow as more states process their filings.

What was actually stolen

The stolen data goes well beyond basic contact information. According to the notices, hackers took names, home addresses, and Social Security numbers. They also got government ID numbers, including passport and driver's license numbers.

On top of that, the breach exposed financial information, including bank account details and payment card numbers, along with what CareCloud described as a substantial amount of medical and health-related data. That combination, Social Security numbers plus financial accounts plus health records, is close to the worst-case mix for identity theft and medical fraud.

CareCloud said a hacker claimed to have exfiltrated data from its databases hosted on Amazon Web Services. The company did not explain how the hacker made that claim, though TechCrunch noted it's common for attackers to share samples of stolen data as proof, often alongside a ransom demand, to pressure victims before threatening to leak everything publicly.

No ransomware or extortion group has publicly taken credit for the CareCloud breach, and TechCrunch found no evidence the stolen data has been posted online. It could mean CareCloud paid a ransom, is still negotiating, or the hackers are sitting on the data for other purposes. There's no confirmation of any of those scenarios, and the company hasn't said.

The company isn't talking

CareCloud CEO Stephen Snyder did not respond to TechCrunch's requests for comment or to specific questions about the breach. Four months after the intrusion started, CareCloud's public disclosure has been thin since day one. The March 27 filing gave regulators the bare minimum. It took until this week's state notices, and TechCrunch's reporting, for the public to learn hackers had roughly a week of unsupervised access and walked away with financial and ID data on top of medical records.

Companies that handle Social Security numbers and medical files for millions of Americans have a basic obligation to tell people, clearly and fast, what happened to their data. Breach investigations do take time. Companies often don't know the full scope of what was taken until forensic investigators finish their work, and premature disclosures can be wrong or incomplete. Rushing out bad information isn't better than a delayed but accurate notice.

But four months of near-total public silence, with no update on whether a ransom was paid, no statement on remediation steps, and no response to a national tech outlet's direct questions, isn't a forensic delay. It's a communications failure. Patients whose Social Security numbers and bank details are sitting with unknown hackers deserve more than a form letter.

Part of a bigger pattern

CareCloud isn't an outlier. TechCrunch noted this is the latest in a string of major 2026 healthcare breaches, including one at revenue tech firm TriZetto affecting 3.4 million people, and a monthlong hack at NYC Health + Hospitals that exposed 1.8 million people's health data.

Healthcare data keeps getting hit because it's valuable and because the industry's cybersecurity hasn't kept pace with how much sensitive data it now stores digitally. Social Security numbers don't expire. Medical histories don't change. That makes healthcare databases a permanent target, and breach notification laws, which vary state by state, are the main mechanism forcing companies to admit what happened at all.

The open questions now are how many more states will report additional victims beyond the 345,000 already confirmed, whether CareCloud paid any ransom, and whether the company will offer more than routine credit monitoring to people whose government ID numbers and bank information are now in unknown hands.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchCareCloud begins to notify hundreds of thousands after hackers stole medical records