Key Takeaways
Craneware Breach Wipes 9.6% | Broker Still Says Buy at 1,700p

- Craneware confirmed hackers exfiltrated employee, customer, and partner data from its systems
- The UK-based firm's software handles billing for thousands of US hospitals and pharmacies
- Healthcare tech vendors have become prime targets, with breaches at TriZetto, CareCloud, and Episource in the past year
Craneware, the UK-based healthcare billing software company used by thousands of US hospitals and pharmacies, disclosed Monday that hackers stole a "significant volume" of customer data from its systems. The company filed a statement with the London Stock Exchange confirming the breach but has not specified what types of sensitive information were taken.
Craneware believes the attackers have been expelled from its network, though the investigation remains open. CEO Keith Neilson did not respond to questions about whether the hackers made ransom demands. Chief Growth Officer Ian Armstrong acknowledged the company was still investigating but declined to comment further.
What data could be at risk?
The company stated only that a "percentage" of employee data, customer data, and partner records had been exfiltrated. That vague description leaves open some troubling possibilities.
Craneware's software helps healthcare providers bill patients for services. This means the company handles medical records and patient data on behalf of its clients. When Craneware acquired Florida-based pharmacy software maker Sentry in 2021, it gained access to 147 million patient records accumulated over two decades.
Whether any of those patient records were compromised remains unclear. The company has not confirmed if its email systems are even operational during the ongoing incident response.
Why healthcare tech vendors keep getting hit
Craneware is the latest in a grim parade of healthcare software companies breached in the past year. The pattern is consistent: attackers target the vendors that aggregate data from many healthcare providers, maximizing the haul from a single intrusion.
In March, TriZetto confirmed hackers stole personal and health data belonging to more than 3.4 million people. That same month, CareCloud reported a breach of electronic health records but has not disclosed the scale. Last July, medical billing company Episource began notifying 5.4 million people that their information had been stolen.
The largest US healthcare breach on record hit Change Healthcare in 2024. A Russian-speaking ransomware gang stole medical and patient records affecting at least 192 million people. UnitedHealth, which owns Change Healthcare, called it a "substantial proportion of people in America."
Healthcare data fetches a premium on criminal markets because it contains enough information for identity theft, insurance fraud, and extortion. Unlike a stolen credit card number, a patient's medical history cannot be reissued.
What hospitals should do now
Craneware has not yet issued specific guidance to its customers. Healthcare providers using the company's software should prepare for breach notifications and consider whether their own data security protocols depend on vendor systems that may have been compromised.
Third-party risk management has become a board-level concern for hospitals. When a billing vendor suffers a breach, the healthcare providers who entrusted them with patient data often share regulatory liability under HIPAA.
Logicity's Take
The Craneware breach underscores why healthcare IT leaders cannot outsource security by outsourcing software. Vendor risk assessments need teeth: audit rights, real-time breach notification clauses, and contractual guarantees about data segmentation. CISOs in healthcare should also be mapping which vendors hold which patient populations. Knowing you use Craneware is not enough. You need to know exactly which data flows through them so you can scope your incident response before the breach hits the news.
The regulatory and legal exposure
Craneware filed its disclosure with the London Stock Exchange, indicating the company considers the breach material to investors. US regulators will likely demand answers too. If protected health information was involved, breach notification requirements under HIPAA's Breach Notification Rule kick in within 60 days of discovery.
For the thousands of US hospitals relying on Craneware's software, the next few weeks will involve uncomfortable questions from compliance officers, legal counsel, and potentially patients.
Another case where software systems were compromised in unexpected ways
Frequently Asked Questions
What does Craneware do?
Craneware makes billing and revenue management software used by thousands of US hospitals, clinics, and pharmacies to bill patients and insurance companies for healthcare services.
How many patient records could be affected?
Craneware has not disclosed the number. However, when the company acquired Sentry in 2021, it gained access to 147 million patient records. Whether those records were compromised is unknown.
What should hospitals using Craneware do?
Hospitals should contact Craneware for details on the breach, review what data they shared with the vendor, and prepare internal incident response protocols in case patient notifications become necessary.
Is this related to ransomware?
Craneware has not confirmed whether a ransom demand was made. The company's CEO did not respond to questions about attacker demands.
Need Help Implementing This?
If your organization needs to strengthen vendor risk management or incident response planning, contact Logicity's advisory team for a consultation.
Source: TechCrunch / Zack Whittaker
Manaal Khan
Tech & Innovation Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.
Related Articles
More in Trending Tech
Humanity Just Went Farther Into Space Than Ever Before — And Made It Back Alive
Four astronauts splashed down in the Pacific Ocean on April 10, 2026, after traveling farther from Earth than any human beings in history. The Artemis II crew shattered a 56-year-old distance record set by Apollo 13, journeying nearly 253,000 miles from our planet during their 10-day lunar flyby mission. This marks the first time humans have ventured beyond low Earth orbit since 1972.

Amflow's Electric Bikes Are Blowing The Competition Away
Amflow, the e-bike brand spun out of DJI, has just released two impressive new electric mountain bikes that are breaking the mold with unprecedented power, range, and lightness. The flagship bikes are powered by the innovative Avinox motors and come with features like onboard navigation and heart rate control.

Canva Just Made a Power Play: Here's What It Means for the Future of Design and Marketing
Canva has made a bold move by acquiring two companies, Simtheory and Ortto, to boost its AI and marketing automation capabilities. This strategic move is set to revolutionize the way teams work on design and marketing projects. With these acquisitions, Canva is poised to become an all-in-one platform for businesses and individuals alike.


