Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

Craneware Cyberattack: Significant Data Stolen from US Healthcare Provider

Edinburgh-based tech firm Craneware has confirmed a cyberattack resulted in the theft of a significant volume of customer data. The company's software is widely used by thousands of US hospitals, pharmacies, and clinics for patient billing.

  • Edinburgh-based Craneware experienced a cyberattack, leading to the theft of significant customer data.
  • The company's software is critical for billing in thousands of US healthcare facilities.
  • A percentage of employee, customer, and partner data was exfiltrated, with an ongoing investigation.
  • This incident is part of a growing trend of cyberattacks targeting US healthcare tech suppliers.

Edinburgh-headquartered tech firm Craneware, a key supplier of billing software to the US healthcare sector, has disclosed a significant cyberattack. The company confirmed on Monday, 20 July 2026, that hackers infiltrated its systems and exfiltrated a substantial volume of customer data. While the company believes the intruders have been expelled, an investigation into the full extent of the breach is currently underway, as stated in a filing with the London Stock Exchange.

Craneware's flagship accounting and billing software is a vital tool for thousands of hospitals, clinics, and pharmacies across the United States. These systems manage patient billing, which often involves handling extensive medical records and sensitive patient health information. The company has not yet specified the exact types of data compromised, only confirming that a 'percentage' of employee data, customer data, and partner records were stolen.

The scale of data potentially exposed is considerable. When Craneware acquired Florida-based pharmacy software maker Sentry in 2021, it gained access to Sentry's database containing 147 million patient records accumulated over two decades. This acquisition highlights the vast amounts of sensitive information Craneware's systems are designed to manage on behalf of its US clients.

This incident follows a concerning trend of cyberattacks targeting technology companies that provide services to the US healthcare sector. In recent months, several other health tech firms have reported breaches. For example, in March, healthcare revenue tech firm TriZetto confirmed hackers stole personal and health data from over 3.4 million individuals. The same month, medical data storage giant CareCloud reported a breach of its electronic health records, though the quantity of data taken was not disclosed. Last July, medical billing company Episource began notifying at least 5.4 million people that their information had been compromised.

The largest breach of US medical and healthcare data occurred in 2024, when a Russian-speaking ransomware group targeted UnitedHealth-owned Change Healthcare. That attack resulted in the theft of medical and patient records belonging to at least 192 million people, which the company acknowledged affected a 'substantial proportion of people in America.' These incidents underscore the increasing vulnerability of critical healthcare infrastructure to sophisticated cyber threats.

Why this matters: While directly impacting US patients and healthcare providers, this incident highlights the global nature of cyber threats and the interconnectedness of digital infrastructure. UK businesses and individuals should be aware of the persistent risk of data breaches, even if the direct impact is overseas.

What this means for you: What this means for you: While this specific cyberattack directly affects US healthcare systems and patients, it serves as a reminder for UK citizens about the importance of digital security. Always be vigilant about protecting your personal data online and be wary of suspicious communications, as cyber threats are a global concern.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.