Software provider to more than 2,000 US hospitals says hackers stole employee and customer data
A British company whose software is used by thousands of U.S. hospitals said Monday that hackers broke into its internal network and stole data on employees, customers and business partners.
Craneware, which is headquartered in Edinburgh and listed on London's AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since brought in outside forensic investigators.
The company said it has reported the incident to the FBI and to Britain’s Information Commissioner’s Office.
According to the company, the intrusion has been contained and the attackers no longer have a foothold in its systems. It added that neither its own operations nor the services it provides to hospitals were disrupted.
The company said a large number of file names were viewed and copied out of its network. Most of that material was non-sensitive or already publicly available regulatory data, but the company confirmed that some employee data and customer and partner records were also taken.
Craneware said it is still working out exactly what was stolen and expects to notify affected organizations and individuals once it does.
The notice does not say who was responsible, when the hackers first got in, how long they had access, or whether an extortion demand was made.
Craneware did not name any of the customers whose records were caught up in the breach, and did not say whether patient information was among the stolen data — a question that would determine whether U.S. health privacy rules apply.
Founded in 1999, Craneware sells billing, pricing and pharmacy software to American healthcare providers, and says it works with more than 2,000 hospitals and close to 10,000 clinics and retail pharmacies.
Hackers have repeatedly targeted healthcare vendors in recent years. In March, software firm CareCloud warned the electronic health records of patients may have been leaked after hackers gained access to its systems.
Two weeks before CareCloud’s warning, the healthcare analytics firm Insightin told state regulators that 1.1 million people were affected by a data theft incident that took place in September.
Another 3 million people had sensitive healthcare data stolen when hackers breached healthcare technology company TriZetto Provider Solutions in 2024 and 5 million were impacted when technology firm Episource was attacked.
Alexander Martin
is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79



