Craneware data breach disclosure says hackers stole a significant volume of customer data from its systems in a cyberattack disclosed on Monday. The company’s software reaches thousands of clinics, hospitals, and pharmacies across the United States, so the exposure matters to organizations that depend on its billing and accounting tools.
Craneware said a percentage of employee data, customer data, and partner records was exfiltrated. The company also said it handles large amounts of medical records and patient data on behalf of its customers, which makes the boundary between ordinary business records and sensitive healthcare information unusually thin.
Keith Neilson and the breach filing
Craneware filed a statement with the London Stock Exchange about the incident. Keith Neilson did not respond to TechCrunch’s questions about the breach, and Ian Armstrong said the company was still investigating.
The company said hackers appear to have been expelled from its systems. That leaves a narrower but still uncomfortable problem for users and customers: whether the affected systems can keep functioning normally while the investigation continues.
What the stolen records could cover
Craneware did not specify exactly what kinds of employee, customer, and partner data were taken. In practice, that matters because those record sets can range from routine contact details to data tied to billing, identity, or patient handling, and the company has said it processes medical records and patient data for customers.
Craneware’s past acquisition of Sentry in 2021 showed the scale of data in this ecosystem. It said at the time that it gained access to 147 million patient records collected over two decades.
Healthcare vendors under attack
The breach fits a pattern that has kept U.S. healthcare software vendors under pressure. TriZetto said in March that hackers stole more than 3.4 million people’s personal and health data from its systems during an earlier cyberattack, and CareCloud reported a breach of one of its stores of patients’ electronic health records in March.
Episource began notifying at least 5.4 million people last July, and Change Healthcare said in 2024 that hackers stole the medical and patient records of at least 192 million people from its systems. For Craneware customers, the practical question is whether any account, billing, or patient-linked records touched by the company need to be treated as exposed until the investigation finishes.
The most urgent unanswered question is what exact kinds of employee, customer, and partner data were stolen from Craneware.







