Cyberattack Exposes Vulnerability in US Healthcare Sector
Craneware, a U.K.-based healthcare billing software maker, has fallen victim to a cyberattack in which hackers stole a ‘significant volume’ of customer data from its systems. The company, which provides accounting and billing software to thousands of clinics, hospitals, and pharmacies across the United States, confirmed the breach in a statement filed with the London Stock Exchange.
While the exact nature of the stolen data remains unclear, Craneware stated that a ‘percentage’ of employee data, customer data, and partner records had been exfiltrated. The company’s software helps healthcare providers bill patients for services and handles large amounts of medical records and patient data on behalf of its customers.
Notably, Craneware’s acquisition of Florida-based pharmacy software maker Sentry in 2021 granted the company access to 147 million patient records collected over two decades. The breach raises concerns about the potential for hackers to access sensitive patient information and extort companies with threats of publicly releasing the data.
As part of its investigation, Craneware has confirmed that the hackers have been expelled from its systems, but the company’s statement noted that the investigation is ongoing. The company’s CEO, Keith Neilson, has not yet responded to TechCrunch’s questions about the incident or whether the hackers have made any demands, such as a ransom.
The cyberattack on Craneware is the latest in a series of data breaches targeting tech companies that supply services to the U.S. healthcare sector. In recent months, healthcare revenue tech firm TriZetto confirmed that hackers stole over 3.4 million people’s personal and health data from its systems, while medical data storage giant CareCloud reported a breach of one of its stores of patients’ electronic health records.
Last July, medical billing company Episource began notifying at least 5.4 million people that their information had been stolen by hackers. The largest ever breach of U.S. medical and healthcare data occurred in 2024, when a Russian-speaking ransomware gang hacked UnitedHealth-owned Change Healthcare, stealing the medical and patient records of at least 192 million people.
The Craneware breach serves as a stark reminder of the vulnerability of the U.S. healthcare sector to cyberattacks. As healthcare providers increasingly rely on digital systems to manage patient data, the risk of data breaches and cyberattacks continues to grow. It is essential for companies like Craneware to prioritize the security and integrity of patient data and take proactive measures to prevent such breaches from occurring in the future.
In the wake of this breach, healthcare providers and tech companies must re-examine their cybersecurity protocols and invest in robust measures to protect sensitive patient information. This includes implementing robust encryption methods, conducting regular security audits, and providing ongoing training to employees on cybersecurity best practices.
The consequences of failing to address these vulnerabilities can be severe, with hackers potentially exploiting sensitive patient information to extort companies or compromise patient care. As the healthcare sector continues to evolve, it is essential that companies like Craneware prioritize the security and integrity of patient data to prevent such breaches from occurring in the future.