Craneware Breach Exposes Employee, Customer Data Amidst Rising Healthcare Vendor Attacks
A significant cybersecurity incident has impacted **Craneware**, a UK-based company providing software to thousands of U.S. hospitals. Hackers infiltrated the company's internal network, exfiltrating data pertaining to employees, customers, and business partners. While operations remained undisrupted, the breach highlights the persistent vulnerability of third-party vendors in the healthcare sector.
A British company whose software is integral to the operations of thousands of U.S. hospitals has confirmed a cyberattack on its internal network. **Craneware**, headquartered in Edinburgh and listed on London's AIM market, disclosed that unauthorized access to a "subset" of its data environment was detected.
The company has engaged outside forensic investigators to probe the incident and has reported it to the **FBI** and Britainβs **Information Commissionerβs Office (ICO)**.
**Craneware** states that the intrusion has been contained, with attackers no longer maintaining a foothold in their systems. Importantly, neither their own operations nor the services provided to hospitals were disrupted.
While a large number of file names were viewed and copied, much of this material was non-sensitive or publicly available regulatory data. However, **Craneware** confirmed the theft of some employee data, as well as customer and partner records.
The full scope of the stolen data is still under investigation. **Craneware** expects to notify affected organizations and individuals once a precise understanding of the exfiltrated information is established.
Details surrounding the attack, including the identity of the perpetrators, the initial point of entry, duration of access, and whether an extortion demand was made, remain undisclosed.
**Craneware**, founded in 1999, specializes in billing, pricing, and pharmacy software for American healthcare providers, serving over 2,000 hospitals and nearly 10,000 clinics and retail pharmacies. The company has not yet specified whether patient information was compromised, a critical detail that would determine the applicability of U.S. health privacy regulations.
### Escalating Threats to Healthcare Vendors
This incident is the latest in a troubling trend of cyberattacks targeting healthcare vendors. In March, software firm **CareCloud** warned of potential patient electronic health record leaks after its systems were breached.
Just weeks prior, healthcare analytics firm **Insightin** reported that 1.1 million individuals were affected by a data theft incident from September. Earlier this year, **TriZetto Provider Solutions** saw sensitive healthcare data stolen from 3 million people, and **Episource** was attacked, impacting 5 million individuals.
