Craneware Hack Hits Healthcare Billing Vendor

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Craneware disclosed in a London Stock Exchange filing that hackers exfiltrated a 'percentage' of employee, customer, and partner data, though the company said the attackers appear to have been expelled and its investigation is ongoing
- Craneware's CEO Keith Neilson did not respond to questions about the breach or any ransom demands; chief growth officer Ian Armstrong said only that the company was still investigating, and it was unclear if its systems could receive email
- Craneware's accounting and billing software is used by thousands of US clinics, hospitals, and pharmacies, and its 2021 acquisition of pharmacy software maker Sentry gave it access to 147 million patient records collected over two decades
- TriZetto confirmed in March that hackers stole personal and health data on more than 3.4 million people from its systems during an earlier cyberattack
- Episource began notifying at least 5.4 million people last July that their information had been stolen, while CareCloud reported a breach of its electronic health record store the same month as the TriZetto disclosure
- The largest US healthcare breach on record was the 2024 ransomware attack by a Russian-speaking gang on UnitedHealth-owned Change Healthcare, which compromised medical and patient records of at least 192 million people
Why it matters: Craneware sits in the billing pipeline for thousands of US healthcare providers, and its Sentry acquisition put 147 million patient records in scope of this breach — exactly the supply-chain chokepoint hackers target. It's the latest in a six-month streak of healthcare tech attacks following Change Healthcare's 192-million-record breach.



