UK’s Craneware hacked: US hospital data stolen – Claril Noticias

UK-based healthcare billing software provider Craneware is investigating a major cyberattack after hackers exfiltrated a significant volume of customer data from its systems on Monday, threatening the privacy of thousands of US hospitals and pharmacies.

Extent of the Craneware Data Breach

Although the company stated that the intruders have now been expelled from its network, the investigation into the security incident remains active, according to an official regulatory filing with the London Stock Exchange.

Craneware’s core financial and billing software is integrated into the systems of thousands of clinics, medical centres, and pharmacies throughout the United States. While the firm has not specified the precise nature of the stolen files, it confirmed that the breach compromised a percentage of employee records, customer data, and partner information.

Millions of Patient Records at Risk

As a key provider of healthcare billing solutions, Craneware processes vast quantities of sensitive medical and billing data. The potential exposure is substantial; following its 2021 acquisition of Florida-based pharmacy software developer Sentry, Craneware said it gained access to a database containing 147 million patient records compiled over two decades.

Craneware Chief Executive Keith Neilson has not responded to inquiries regarding the breach or whether the attackers have issued ransom demands. Following the initial disclosure, Chief Growth Officer Ian Armstrong confirmed that the internal investigation is ongoing but declined to provide further details. It also remains uncertain whether the company’s email systems are fully operational following the disruption.

A Growing Threat to Healthcare Cybersecurity

This incident represents the latest in a series of cyberattacks targeting third-party technology providers within the US healthcare sector. By infiltrating the software platforms that healthcare organisations rely on to analyse and manage billing processes, cybercriminals can harvest massive volumes of patient data to extort companies under the threat of public exposure.

Other Recent Healthcare Security Breaches

Craneware joins a growing list of major health-tech firms compromised over the past year. In March, healthcare revenue technology specialist TriZetto revealed that hackers had accessed the personal and medical data of over 3.4 million individuals during a prior breach. That same month, electronic health records provider CareCloud disclosed a breach affecting one of its data storage systems, though the total volume of compromised data remains unconfirmed.

Additionally, medical billing firm Episource began notifying approximately 5.4 million individuals last July that their personal details had been stolen in a cyberattack.

The Change Healthcare Precedent

These incidents follow the largest-ever cyberattack on the US healthcare system in early 2024, when a Russian-speaking ransomware syndicate breached UnitedHealth Group subsidiary Change Healthcare. The attackers exfiltrated the medical and personal records of at least 192 million people, a breach that the company acknowledged impacted a substantial proportion of the American public.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *