OTHER

Hackers Breach Leading Tech Firm Supporting Thousands of US Hospitals and Pharmacies, Compromising Sensitive Data

Craneware, a U.K.-based provider of healthcare billing software, is currently dealing with a cyberattack that has led to the theft of a “significant volume” of customer data, as reported by the company on Monday.

In a statement to the London Stock Exchange, the organization noted that they believe the hackers have been eliminated from their systems, although an investigation into the breach is still in progress.

Craneware’s primary accounting and billing software is used by numerous clinics, hospitals, and pharmacies across the United States. The company has not specified the types of data that were compromised, merely indicating that a “percentage” of employee information, customer data, and partner records were accessed.

Craneware oversees a large volume of medical records and patient information on behalf of its clients, providing software that assists healthcare providers in billing patients for the services they have received. After acquiring Sentry, a pharmacy software firm based in Florida, in 2021, Craneware gained access to 147 million patient records gathered over the previous two decades.

Craneware CEO Keith Neilson did not respond to TechCrunch’s questions about the incident, including whether the hackers made any demands, such as ransom. Following the publication of the article, Craneware’s chief growth officer Ian Armstrong noted that the company was still investigating but did not provide any additional comments.

It is currently unclear whether the company’s systems are capable of receiving emails, as the cyberattack is still ongoing.

While the details of the breach are under review, this incident is part of an increasing trend of data breaches affecting technology companies in the U.S. healthcare sector in recent months. By breaching software widely used by healthcare providers for billing, hackers can access extensive medical and health-related information, raising the possibility of public release for extortion.

Craneware is the latest technology giant in the healthcare sector to fall victim to a breach this year.

In March, TriZetto, a healthcare revenue technology company, confirmed that hackers had stolen the personal and health information of over 3.4 million individuals during a previous cyberattack. That same month, CareCloud, a prominent medical data storage provider, reported a breach affecting patient electronic health records, although the extent of the data stolen remains unspecified.

Last July, medical billing service Episource began notifying at least 5.4 million individuals that their information had been compromised by hackers.

The most significant breach of medical and healthcare data in the U.S. took place in 2024 when a Russian-speaking ransomware group infiltrated Change Healthcare, owned by UnitedHealth, stealing medical and patient records of at least 192 million individuals. The company acknowledged that this incident impacted a “substantial proportion of people in America.”

Updated with a response from Craneware.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.