U.K.-based healthcare billing software provider Craneware has disclosed a significant data breach, with hackers exfiltrating a substantial volume of customer data from its systems. The company, whose software is utilized by thousands of clinics, hospitals, and pharmacies across the United States, is currently investigating the extent of the intrusion.
In a statement filed with the London Stock Exchange, Craneware indicated that the attackers have been expelled from their systems. However, the investigation is ongoing to determine the full scope of the breach. The company has not specified the exact types of data compromised but acknowledged that a portion of employee, customer, and partner records were accessed.
Craneware’s software plays a critical role in assisting healthcare providers with billing and accounting processes, handling vast amounts of medical records and patient data. The 2021 acquisition of Florida-based pharmacy software maker Sentry expanded Craneware’s access to 147 million patient records accumulated over two decades.
CEO Keith Neilson has not provided further details regarding the incident or whether the hackers have made any demands, such as a ransom. It remains unclear if the company’s communication systems, including email, are fully operational amid the ongoing investigation.
This breach is part of a troubling trend of cyberattacks targeting technology firms that supply services to the U.S. healthcare sector. By infiltrating software used by numerous healthcare providers, hackers can access extensive patient medical and health-related data, potentially leveraging this information for extortion.
In recent months, several health tech companies have reported similar breaches. In March, TriZetto confirmed that hackers stole personal and health data of over 3.4 million individuals during a previous cyberattack. That same month, CareCloud reported a breach involving patient electronic health records, though the extent of the data taken has not been disclosed. Additionally, in July, medical billing company Episource began notifying at least 5.4 million people that their information had been compromised.
The largest known breach in the U.S. healthcare sector occurred in 2024 when a ransomware gang infiltrated Change Healthcare, a subsidiary of UnitedHealth. The attackers stole medical and patient records affecting at least 192 million individuals, a substantial portion of the American population.
These incidents underscore the critical need for robust cybersecurity measures within the healthcare industry. As healthcare providers increasingly rely on third-party software for billing and data management, ensuring the security of these systems is paramount to protect sensitive patient information and maintain trust in healthcare services.