Craneware confirms hackers stole ‘significant volume’ of data from healthcare billing platform

Craneware, a U.K.-based company that makes accounting and billing software for U.S. healthcare providers, is dealing with a serious cyberattack after hackers broke into its systems and made off with a large amount of customer data. The company confirmed the breach in a statement filed with the London Stock Exchange, saying it believes the hackers have now been removed from its systems, though the investigation is still ongoing.

Craneware’s software is used by thousands of clinics, hospitals, and pharmacies across the United States. The company said a percentage of employee data, customer data, and partner records were taken, but stopped short of giving specifics about exactly what types of data were involved. CEO Keith Neilson did not respond to questions about the incident, including whether the attackers had made any ransom demands. Chief growth officer Ian Armstrong confirmed the investigation was continuing but offered no further comment.

The scale of what Craneware holds makes this breach particularly serious. The company handles large amounts of medical records and patient data on behalf of its clients. When it acquired Florida-based pharmacy software firm Sentry in 2021, Craneware gained access to 147 million patient records collected over two decades. That puts an enormous amount of sensitive health information in scope.

This attack fits a pattern that has become increasingly common. Hackers have been targeting tech companies that supply software and services to the U.S. healthcare sector, because breaching one vendor can expose data from dozens or even hundreds of healthcare providers at once. By getting into billing and analytics platforms, attackers can access vast stores of medical and financial records, then threaten to release that information publicly unless they are paid.

Craneware is not alone. Several health tech companies have been hit in the past year:

  • In March, healthcare revenue firm TriZetto confirmed hackers stole personal and health data belonging to more than 3.4 million people.
  • Also in March, medical data storage company CareCloud reported a breach of patient electronic health records, though the number of people affected has not been disclosed.
  • Last July, medical billing company Episource started notifying at least 5.4 million people that their data had been stolen.

The backdrop to all of this is the 2024 Change Healthcare attack, still the largest breach of U.S. medical data on record. A Russian-speaking ransomware gang hacked UnitedHealth-owned Change Healthcare and stole records belonging to at least 192 million people. UnitedHealth acknowledged the attack affected a substantial proportion of Americans, and the fallout disrupted pharmacy and hospital billing systems across the country for weeks.

That attack made clear just how damaging a single breach at a widely used healthcare software provider can be. Craneware occupies a similar position in the U.S. healthcare supply chain. Until the investigation concludes, the full impact of this breach will remain unknown, but the combination of the company’s reach and the sensitivity of the data it holds means the consequences could be significant.