UK-based healthcare billing software maker Craneware is responding to a cyberattack in which hackers stole a “significant amount” of customer data from its systems, the company said Monday.
The company said the hackers appear to have been removed from its systems, but its investigation into the breach is ongoing, according to a statement filed with the London Stock Exchange.
Craneware’s leading accounting and billing software is used by thousands of clinics, hospitals and pharmacies across the United States. The company did not say exactly what kind of data was taken in the breach, noting only that a “percentage” of employee data, customer data and partner files were compromised.
The company, whose software helps healthcare providers bill patients for services, handles large volumes of medical records and patient data on behalf of its clients. When it bought Florida-based pharmacy software maker Sentry in 2021, Craneware said he gained access in the company’s 147 million patient records that had been collected over two decades.
Craneware CEO Keith Neilson did not respond to TechCrunch’s questions about the incident or whether the hackers have contacted the company with any demands, such as a ransom. After publication, Craneware’s chief development officer Ian Armstrong said the company was continuing to investigate, but did not comment further on the incident.
It is not yet clear whether the company’s systems can receive emails amid the ongoing cyber attack.
While the details of the hack are still under investigation, this is the latest data breach in recent months where hackers have targeted technology companies that provide technology and services to the US healthcare sector. By compromising software that many healthcare providers use to analyze and understand their billing processes, hackers can access vast amounts of patient medical and health-related data and blackmail companies with threats of public disclosure of the information.
Craneware is the latest health tech giant to be hacked in the past year.
In March, healthcare revenue technology company TriZetto confirmed that hackers stole the personal and health data of more than 3.4 million people from its systems during a previous cyber attack. That same month, medical data storage giant CareCloud reported a breach of one of its stores of electronic patient health records, but has yet to say how much data was taken.
Last July, medical billing company Episource began notifying at least 5.4 million people that their information had been stolen by hackers.
The largest medical and healthcare data breach in the US occurred in 2024, when a Russian-speaking ransomware gang breached UnitedHealth-owned Change Healthcare. The hackers stole the medical and patient records of at least 192 million people, which the company admitted affected a “significant percentage of people in America.”
Updated with response from Craneware.
When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.
