Edinburgh-headquartered tech firm Craneware, a key supplier of billing software to the US healthcare sector, has disclosed a significant cyberattack. The company confirmed on Monday, 20 July 2026, that hackers infiltrated its systems and exfiltrated a substantial volume of customer data. While the company believes the intruders have been expelled, an investigation into the full extent of the breach is currently underway, as stated in a filing with the London Stock Exchange.
Craneware's flagship accounting and billing software is a vital tool for thousands of hospitals, clinics, and pharmacies across the United States. These systems manage patient billing, which often involves handling extensive medical records and sensitive patient health information. The company has not yet specified the exact types of data compromised, only confirming that a 'percentage' of employee data, customer data, and partner records were stolen.
The scale of data potentially exposed is considerable. When Craneware acquired Florida-based pharmacy software maker Sentry in 2021, it gained access to Sentry's database containing 147 million patient records accumulated over two decades. This acquisition highlights the vast amounts of sensitive information Craneware's systems are designed to manage on behalf of its US clients.
This incident follows a concerning trend of cyberattacks targeting technology companies that provide services to the US healthcare sector. In recent months, several other health tech firms have reported breaches. For example, in March, healthcare revenue tech firm TriZetto confirmed hackers stole personal and health data from over 3.4 million individuals. The same month, medical data storage giant CareCloud reported a breach of its electronic health records, though the quantity of data taken was not disclosed. Last July, medical billing company Episource began notifying at least 5.4 million people that their information had been compromised.
The largest breach of US medical and healthcare data occurred in 2024, when a Russian-speaking ransomware group targeted UnitedHealth-owned Change Healthcare. That attack resulted in the theft of medical and patient records belonging to at least 192 million people, which the company acknowledged affected a 'substantial proportion of people in America.' These incidents underscore the increasing vulnerability of critical healthcare infrastructure to sophisticated cyber threats.