All posts

Craneware breach exposes US hospital billing data

Manaal KhanJuly 22, 2026 at 6:31 AM4 min read
Craneware breach exposes US hospital billing data

Key Takeaways

Craneware Breach Wipes 9.6% | Broker Still Says Buy at 1,700p

Craneware breach exposes US hospital billing data
Source: TechCrunch
  • Craneware confirmed hackers exfiltrated employee, customer, and partner data from its systems
  • The UK-based firm's software handles billing for thousands of US hospitals and pharmacies
  • Healthcare tech vendors have become prime targets, with breaches at TriZetto, CareCloud, and Episource in the past year

Craneware, the UK-based healthcare billing software company used by thousands of US hospitals and pharmacies, disclosed Monday that hackers stole a "significant volume" of customer data from its systems. The company filed a statement with the London Stock Exchange confirming the breach but has not specified what types of sensitive information were taken.

Craneware believes the attackers have been expelled from its network, though the investigation remains open. CEO Keith Neilson did not respond to questions about whether the hackers made ransom demands. Chief Growth Officer Ian Armstrong acknowledged the company was still investigating but declined to comment further.

Advertisements

What data could be at risk?

The company stated only that a "percentage" of employee data, customer data, and partner records had been exfiltrated. That vague description leaves open some troubling possibilities.

Craneware's software helps healthcare providers bill patients for services. This means the company handles medical records and patient data on behalf of its clients. When Craneware acquired Florida-based pharmacy software maker Sentry in 2021, it gained access to 147 million patient records accumulated over two decades.

Whether any of those patient records were compromised remains unclear. The company has not confirmed if its email systems are even operational during the ongoing incident response.

Why healthcare tech vendors keep getting hit

Craneware is the latest in a grim parade of healthcare software companies breached in the past year. The pattern is consistent: attackers target the vendors that aggregate data from many healthcare providers, maximizing the haul from a single intrusion.

In March, TriZetto confirmed hackers stole personal and health data belonging to more than 3.4 million people. That same month, CareCloud reported a breach of electronic health records but has not disclosed the scale. Last July, medical billing company Episource began notifying 5.4 million people that their information had been stolen.

The largest US healthcare breach on record hit Change Healthcare in 2024. A Russian-speaking ransomware gang stole medical and patient records affecting at least 192 million people. UnitedHealth, which owns Change Healthcare, called it a "substantial proportion of people in America."

Healthcare data fetches a premium on criminal markets because it contains enough information for identity theft, insurance fraud, and extortion. Unlike a stolen credit card number, a patient's medical history cannot be reissued.

Advertisements

What hospitals should do now

Craneware has not yet issued specific guidance to its customers. Healthcare providers using the company's software should prepare for breach notifications and consider whether their own data security protocols depend on vendor systems that may have been compromised.

Third-party risk management has become a board-level concern for hospitals. When a billing vendor suffers a breach, the healthcare providers who entrusted them with patient data often share regulatory liability under HIPAA.

ℹ️

Logicity's Take

The Craneware breach underscores why healthcare IT leaders cannot outsource security by outsourcing software. Vendor risk assessments need teeth: audit rights, real-time breach notification clauses, and contractual guarantees about data segmentation. CISOs in healthcare should also be mapping which vendors hold which patient populations. Knowing you use Craneware is not enough. You need to know exactly which data flows through them so you can scope your incident response before the breach hits the news.

The regulatory and legal exposure

Craneware filed its disclosure with the London Stock Exchange, indicating the company considers the breach material to investors. US regulators will likely demand answers too. If protected health information was involved, breach notification requirements under HIPAA's Breach Notification Rule kick in within 60 days of discovery.

For the thousands of US hospitals relying on Craneware's software, the next few weeks will involve uncomfortable questions from compliance officers, legal counsel, and potentially patients.

Also Read
OpenAI's pre-release models breached Hugging Face during test

Another case where software systems were compromised in unexpected ways

Frequently Asked Questions

What does Craneware do?

Craneware makes billing and revenue management software used by thousands of US hospitals, clinics, and pharmacies to bill patients and insurance companies for healthcare services.

How many patient records could be affected?

Craneware has not disclosed the number. However, when the company acquired Sentry in 2021, it gained access to 147 million patient records. Whether those records were compromised is unknown.

What should hospitals using Craneware do?

Hospitals should contact Craneware for details on the breach, review what data they shared with the vendor, and prepare internal incident response protocols in case patient notifications become necessary.

Is this related to ransomware?

Craneware has not confirmed whether a ransom demand was made. The company's CEO did not respond to questions about attacker demands.

ℹ️

Need Help Implementing This?

If your organization needs to strengthen vendor risk management or incident response planning, contact Logicity's advisory team for a consultation.

Source: TechCrunch / Zack Whittaker

M

Manaal Khan

Tech & Innovation Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.

Related Articles