Key Takeaways

  • Craneware, a healthcare billing software firm, suffered a data breach.
  • The company is investigating the incident and has expelled the hackers.
  • Data stolen includes employee and customer information.
  • This breach adds to a series of recent attacks on healthcare tech companies.

Data Breach Details

Craneware, a UK-based company that provides billing software for healthcare, reported a cyberattack that resulted in the theft of a significant amount of customer data. The firm stated on Monday that it has managed to remove the hackers from its systems, but the investigation into the breach is still ongoing.

Impact on Healthcare Providers

The software developed by Craneware is widely used by clinics, hospitals, and pharmacies throughout the United States. While the company has not disclosed the specific types of data that were compromised, it acknowledged that a portion of employee data, customer information, and partner records were taken.

Company’s Response

Craneware’s CEO Keith Neilson did not provide comments regarding the incident or whether the hackers made any ransom demands. Ian Armstrong, the chief growth officer, mentioned that the investigation is still in progress but did not elaborate further.

Ongoing Cybersecurity Concerns

As the investigation continues, it remains uncertain if Craneware’s email systems are operational. This incident is part of a troubling trend, with hackers increasingly targeting technology firms that support the U.S. healthcare sector. By breaching software used for billing processes, attackers can gain access to vast amounts of sensitive patient data and threaten companies with public exposure of this information.

Recent Trends in Healthcare Data Breaches

Craneware is not alone in facing such challenges. Earlier this year, TriZetto confirmed that hackers accessed the personal and health data of over 3.4 million individuals. Similarly, CareCloud reported a breach involving patient electronic health records, although details on the extent of the data taken remain unclear. Last July, Episource informed at least 5.4 million individuals that their information had been compromised.

The largest breach in U.S. medical data history occurred in 2024 when a ransomware group hacked Change Healthcare, affecting the records of at least 192 million people.