Software provider to more than 2,000 US hospitals says hackers stole employee and customer data
Craneware, a UK-based software provider used by over 2,000 U.S. hospitals, has been hacked, resulting in the theft of employee, customer, and partner data. The company has contained the breach and reported it to law enforcement, but is still investigating the extent of the data compromised and identifying the attackers. This follows a recent trend of attacks targeting healthcare vendors, raising significant privacy concerns.
Craneware, a British software provider, announced that hackers had gained unauthorized access to its internal network, leading to the theft of data pertaining to employees, customers, and business partners. The company, headquartered in Edinburgh and listed on London's AIM market, detected the intrusion and subsequently engaged outside forensic investigators to assess the situation. Craneware has reported the incident to the FBI and Britain’s Information Commissioner’s Office.
According to Craneware, a significant number of file names were viewed and copied from its network. While most of the material accessed was non-sensitive or already publicly available regulatory data, the company confirmed that some employee data and customer and partner records were also compromised. Craneware is currently working to determine precisely what data was stolen and intends to notify affected organizations and individuals once the investigation is complete.
Founded in 1999, Craneware provides billing, pricing, and pharmacy software to American healthcare providers, serving over 2,000 hospitals and nearly 10,000 clinics and retail pharmacies. The incident follows a pattern of attacks against healthcare technology vendors, including recent breaches at CareCloud, Insightin, and TriZetto Provider Solutions, impacting millions of patients and healthcare professionals. The company has not yet identified the attackers or determined whether patient information was included in the stolen data, a crucial factor in determining whether U.S. health privacy regulations apply.
