17 days ago
TechCrunch Jul 20, 2026

Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies

Edinburgh-based Craneware, a healthcare billing software provider relied upon by thousands of hospitals, clinics, and pharmacies across the United States, announced it suffered a cyberattack that resulted in the theft of a “significant volume” of customer, employee, and partner data. The company has reportedly removed the hackers from its systems and is actively investigating the breach, though details about the specific types of data exfiltrated remain limited. Craneware handles substantial amounts of medical records and patient billing data, amplifying concerns about the potential exposure of sensitive health information.

Craneware acquired Florida-based pharmacy software maker Sentry in 2021, gaining access to around 147 million patient records collected over two decades. Despite repeated questions from TechCrunch, Craneware’s CEO Keith Neilson has not commented publicly on whether any ransom demands have been made by the attackers, and the company’s chief growth officer Ian Armstrong indicated only that the investigation is ongoing. It is also unclear whether company communication systems, such as email, have been fully restored amid the cyberincident.

This attack underscores a troubling trend in recent months, where tech firms servicing the U.S. healthcare sector have become prime targets for hackers aiming to access vast troves of patient medical and billing data. Other notable breaches include those affecting healthcare firm TriZetto in March, CareCloud, and last July's notification by medical billing company Episource to over 5 million individuals about stolen data. The largest healthcare breach to date occurred in 2024, when ransomware attackers compromised UnitedHealth-owned Change Healthcare’s systems, impacting data of at least 192 million Americans.

The Craneware breach highlights the critical vulnerability of healthcare tech providers that manage sensitive data on behalf of numerous institutions. With hackers increasingly exploiting such software platforms to gain expansive access to private health information, ongoing cybersecurity vigilance and rapid incident response remain essential to limiting the scope and impact of these violations on the healthcare system and patient privacy.

0
0 Read source
Share this post
Facebook Twitter LinkedIn

Discussion

0 comments

No comments yet

Start the discussion with a take, question, or market read.