Craneware, a British software company that sells billing, pricing and pharmacy tools to thousands of U.S. healthcare sites, said hackers got into part of its internal data environment and copied information tied to employees, customers and business partners.
The Edinburgh-based company disclosed the incident to investors on Monday through a notice filed with the London Stock Exchange. Craneware said it has hired external forensic specialists and reported the breach to both the FBI and the U.K. Information Commissioner’s Office.
For hospitals and clinics that rely on the company’s products, the most immediate point is operational: Craneware said its services were not interrupted and that its own business operations were not disrupted. The company also said the intrusion has been contained and that the attackers no longer have access to its systems.
The disclosure leaves several material questions unanswered. Craneware did not say who it believes carried out the intrusion, when the attackers first entered its network, how long they remained there, or whether anyone demanded payment. It also did not name affected customers.
What Craneware says was taken
According to Craneware, the attackers viewed and copied many file names from its network. The company said most of the material involved was either non-sensitive or already public regulatory information. Craneware also confirmed, however, that some employee information and records belonging to customers and partners were taken.
The company said it is still reviewing the stolen data to determine the exact contents. Craneware said it expects to notify affected organizations and individuals after that work is complete.
The notice does not say whether patient information was included. That is not a clerical detail. If the stolen records include protected health information, the incident could trigger U.S. healthcare privacy reporting requirements. Craneware has not said that such data was taken.
A vendor with a large healthcare footprint
Craneware was founded in 1999 and is listed on London’s AIM market. The company says its software is used by more than 2,000 hospitals and nearly 10,000 clinics and retail pharmacies. Its products sit in the administrative and revenue machinery of healthcare, including billing, pricing and pharmacy operations.
That kind of vendor position can make a breach messy even when hospital systems stay online. A software supplier may hold records from many organizations, and those organizations may then need their own answers about what data moved, whose data it was, and whether regulators must be told.
Craneware’s disclosure comes during a run of attacks on healthcare technology and services companies. In March, CareCloud warned that patient electronic health records may have been exposed after attackers accessed its systems. Around the same period, healthcare analytics company Insightin told state regulators that 1.1 million people were affected by a September data theft incident.
Other recent breaches have been larger. TriZetto Provider Solutions said hackers stole sensitive healthcare data affecting 3 million people in 2024, and technology firm Episource reported an attack affecting 5 million people.
Craneware has said less than many customers will want to know. For now, the confirmed facts are narrower: attackers entered a subset of its data environment, copied files, and left the company sorting through what was exposed.
This story draws on original reporting from The Record.