Craneware, which provides critical accounting and billing infrastructure to the American healthcare sector, filed a statement with the London Stock Exchange regarding the security failure. The company handles sensitive medical records and billing data on behalf of its clients, a scale that expanded significantly following its 2021 acquisition of Florida-based Sentry, which brought 147 million patient records under its purview. CEO Keith Neilson has not addressed whether the breach involved ransom demands or if the company's communication channels remain compromised.
Craneware suffers major data breach affecting US healthcare providers
Thousands of US hospitals and pharmacies face uncertainty after UK-based billing software provider Craneware confirmed a significant volume of data was exfiltrated from its systems. While the company maintains that hackers have been expelled, the ongoing investigation leaves the exact nature of the compromised records—including patient and employee information—undisclosed.

This incident mirrors a growing trend of cyberattacks targeting the software supply chain of the US medical industry. By striking service providers like Craneware, attackers gain a gateway to vast repositories of personal health information. Recent history underscores the severity of such vulnerabilities: TriZetto, CareCloud, and Episource have all reported major exfiltrations in the past year. The scale of these threats remains daunting, particularly following the 2024 attack on Change Healthcare, where a ransomware group compromised the records of at least 192 million people.




Comments (0)
No comments yet. Be the first!