U.Okay.-based healthcare billing software program maker Craneware is responding to a cyberattack by which hackers stole a “important quantity” of buyer knowledge from its methods, the corporate mentioned on Monday.
The corporate mentioned the hackers seem to have been expelled from its methods, however its investigation into the breach is ongoing, in line with an announcement filed with the London Stock Exchange.
Craneware’s flagship accounting and billing software program is utilized by 1000’s of clinics, hospitals, and pharmacies throughout the USA. The corporate didn’t say precisely what sorts of knowledge had been taken within the breach, solely noting {that a} “share” of worker knowledge, buyer knowledge, and associate data had been exfiltrated.
The corporate, whose software program helps healthcare suppliers invoice sufferers for providers, handles massive quantities of medical data and affected person knowledge on behalf of its prospects. When it purchased Florida-based pharmacy software program maker Sentry in 2021, Craneware said it gained access to the corporate’s 147 million affected person data that had been collected over twenty years.
Craneware CEO Keith Neilson didn’t reply to TechCrunch’s questions in regards to the incident, or if the hackers have contacted the corporate with any calls for, resembling a ransom. After publication, Craneware’s chief development officer Ian Armstrong mentioned the corporate was nonetheless investigating, however didn’t touch upon the incident additional.
It’s not but clear if the corporate’s methods can obtain electronic mail amid the continuing cyberattack.
Whereas particulars of the hack are nonetheless underneath investigation, that is the newest knowledge breach in latest months the place hackers have focused tech firms that provide tech and providers to the U.S. healthcare sector. By compromising software program that many healthcare suppliers use to research and perceive their billing processes, hackers can entry huge quantities of affected person medical and health-related knowledge, and extort the businesses with threats of publicly releasing the data.
Craneware is the newest well being tech large to be breached previously yr.
In March, healthcare income tech agency TriZetto confirmed hackers stole more than 3.4 million people’s personal and health data from its methods throughout an earlier cyberattack. That very month, medical knowledge storage large CareCloud reported a breach of one among its stores of patients’ electronic health records, however has not but mentioned how a lot knowledge was taken.
Final July, medical billing firm Episource began notifying at least 5.4 million people that their info had been stolen by hackers.
The biggest-ever breach of U.S. medical and healthcare knowledge occurred in 2024, when a Russian-speaking ransomware gang hacked UnitedHealth-owned Change Healthcare. The hackers stole the medical and affected person data of at least 192 million people, which the corporate conceded affected a “substantial proportion of individuals in America.”
Up to date with a response from Craneware.
If you buy by hyperlinks in our articles, we may earn a small commission. This doesn’t have an effect on our editorial independence.

