Craneware Data Breach Exposes Employee and Customer Information
Software provider Craneware, serving over 2,000 U.S. hospitals, has reported a data breach impacting employee and customer data after hackers accessed its internal network.

Edinburgh-based software provider Craneware announced on Monday that cybercriminals breached its internal network, compromising sensitive data belonging to employees, customers, and business partners. The company, which is listed on London's AIM market and provides essential billing, pricing, and pharmacy software to more than 2,000 U.S. hospitals and nearly 10,000 clinics, detected unauthorized access to a portion of its data environment.
Following the detection of the intrusion, Craneware promptly engaged external forensic investigators and notified both the FBI and the UK's Information Commissioner's Office. The company stated that the breach has been contained and the attackers no longer have access to its systems. Crucially, Craneware assured stakeholders that its own operations and the services it provides to healthcare facilities remained uninterrupted.
While the full scope of the stolen data is still under investigation, Craneware confirmed that a significant number of file names were viewed and copied. Although much of this data consisted of non-sensitive or publicly available regulatory information, the company acknowledged that some employee records and customer and partner data were also exfiltrated. Craneware is in the process of identifying precisely what information was compromised and plans to notify affected parties once this assessment is complete.
The company has not disclosed the identity of the attackers, the timeline of the breach, the duration of the hackers' access, or whether any ransom demands were made. Craneware also withheld the names of affected customers and did not specify if patient data was involved, which would trigger U.S. health privacy regulations.
This incident highlights a persistent trend of threat actors targeting vendors within the healthcare sector. In recent months, other healthcare technology firms have also fallen victim to significant data breaches. Software firm CareCloud warned of potential patient data leaks in March, while healthcare analytics firm Insightin reported a theft incident affecting 1.1 million individuals. Prior incidents include breaches at TriZetto Provider Solutions and Episource, impacting millions more.
Craneware, founded in 1999, plays a critical role in the U.S. healthcare revenue cycle management. Its extensive client base means that a breach at this vendor could have far-reaching implications for numerous healthcare organizations and potentially their patients, depending on the nature of the data stolen.
The lack of immediate attribution and details surrounding the breach underscores the challenges in investigating and mitigating sophisticated cyberattacks. The ongoing nature of these attacks against healthcare providers and their suppliers necessitates continuous vigilance and robust security measures across the entire ecosystem.
Organizations relying on third-party software providers, especially in critical sectors like healthcare, must ensure comprehensive due diligence and maintain strong contractual agreements regarding data security and breach notification protocols.