Technology

Craneware reports cyberattack data theft

UK healthcare billing vendor serves thousands of US hospitals and pharmacies, breach disclosure offers scale but few specifics

Images

Zack Whittaker Zack Whittaker techcrunch.com

Craneware says hackers stole a “significant volume” of customer data from its systems, a breach the UK-based healthcare billing software provider disclosed in a statement filed with the London Stock Exchange. The company said the intruders appear to have been expelled, but its investigation remains ongoing and it has not specified what categories of data were taken. Craneware’s flagship accounting and billing tools are used by thousands of clinics, hospitals and pharmacies across the United States, according to TechCrunch.

The incident lands in a sector where scale is the product: billing platforms sit between patient care and payment, touching identity data, insurance details, and often clinical information that helps justify charges. Craneware acknowledged that a “percentage” of employee data, customer data and partner records were exfiltrated, a phrasing that signals partial loss without giving customers enough detail to assess exposure. The company also did not say whether the attackers made demands, leaving open the most common business model in healthcare breaches: leveraging stolen records for extortion by threatening publication.

Craneware’s position in the supply chain matters because healthcare providers increasingly outsource the plumbing of revenue collection to specialist vendors. When one vendor serves many institutions, a single compromise can become a multi-hospital incident without any of the hospitals being directly breached. TechCrunch notes that Craneware acquired Florida-based pharmacy software maker Sentry in 2021, a deal that brought access to 147 million patient records collected over two decades. Consolidation simplifies procurement for hospitals but concentrates risk for patients whose data travels through systems they have never heard of.

The breach also fits a pattern seen over the past year: attackers targeting the companies behind healthcare operations rather than individual clinics. TechCrunch points to earlier incidents including TriZetto’s confirmation that hackers stole personal and health data from more than 3.4 million people, and Episource’s notifications to at least 5.4 million people after a theft of information. The largest known case remains the 2024 attack on UnitedHealth-owned Change Healthcare, which the company said affected a “substantial proportion of people in America” and involved at least 192 million people.

Craneware has not said whether patient records were among the stolen data, or which customers were affected. For now, the company’s public disclosure is limited to the fact that a large, shared billing and pharmacy software provider lost control of some portion of the data it was holding for others.