25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Major Healthcare Software Vendor Investigating Cyberattack

The healthcare technology company Craneware is investigating a cybersecurity incident and has confirmed that a significant amount of data was stolen in the attack, including employee data and some customer and partner records.

Craneware is a UK company that heavily targets U.S. healthcare companies. The company makes healthcare accounting and billing software, and partners with 2,000  hospitals and health systems, and around 10,000 pharmacies and clinics, many of which are located in the United States. According to the Craneware website, its software and Trisus cloud platform underpin around 165 million unique patient encounters and impact half a trillion healthcare dollars. In 2021, the company acquired the pharmacy software vendor Sentry, providing the company with access to almost 150 million patient records.

Craneware reports that the company quickly implemented its incident response plan and contained the incident, without any disruption to customer services or the company’s operations. The external investigators assisting with the response have not found any further signs of compromise, which indicates that the hackers have been ejected from its network.

While the review of the impacted data is still in the early stages, the company has confirmed that “a significant volume of file names were viewed and exfiltrated” by the hackers before they were ejected from its systems. “A percentage of Craneware employee data as well as a subset of customer and partner records have been accessed and exfiltrated,” explained the company in its cybersecurity incident notice. “The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data.” The company has yet to confirm how many patient records were accessed, only stating that a minority of the records it holds have been compromised. Given the volume of data held by the company, that could still represent a significant data breach.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The cyberattack has been reported to the UK’s data watchdog, the Information Commissioner’s Office (ICO), and the U.S. Federal Bureau of Investigation (FBI). The company has not yet disclosed the threat actor or group behind the attack, when access to its environment was gained, when the attack was discovered, or the names of affected customers.

“The company is continuing to assess the precise nature and scope of all the data involved and is working with its advisers to identify affected parties and prepare appropriate notifications, including any required further notifications to relevant authorities, in each case in accordance with applicable regulatory obligations,” explained the company. It is currently unclear whether this was a data theft and extortion incident and if a ransom demand has been issued. No hacking group appears to have claimed responsibility for the attack.

There has been a spate of recent cyberattacks on healthcare vendors, including software providers and medical device companies. Vendors often work with large numbers of healthcare clients and store or have access to large volumes of sensitive patient data, so they are attractive targets for hackers.

“A breach inside one hospital can shut down local systems and disrupt care in a visible way. A breach at a shared technology provider creates a different problem. Operations may keep running, but the potential blast radius stretches across thousands of customers that depend on the same platform. That uncertainty can become its own disruption. Hospitals may need to review exposed records, watch for phishing, rotate credentials, and verify that vendor connections remain trustworthy. Smaller providers may feel the strain most because they often lack the staff to investigate a third-party incident while keeping daily operations moving,” Ross Filipek, CISO at Corsica Technologies, told the HIPAA Journal. “At-risk organizations should identify every connection to the provider, limit unnecessary access, and monitor for unusual activity. They should also confirm what data was shared and test contingency plans. A vendor breach should be treated as an active incident, not someone else’s cleanup.”

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist