Craneware confirms significant data breach affecting US healthcare billing systems
The firm, which supplies accounting tools to thousands of US clinics and pharmacies, says attackers have been expelled from its systems, though the full scope of stolen sensitive health data remains unclear.

Craneware, a UK-based healthcare billing software provider, has confirmed that hackers stole a significant volume of customer data during a cyberattack. The Edinburgh-headquartered firm, which supplies accounting and billing software to thousands of hospitals, pharmacies, and clinics across the United States, stated in a statement filed with the London Stock Exchange on Monday that the attackers appear to have been expelled from its systems. An investigation into the breach is currently ongoing.
The company did not specify the exact nature or volume of the data taken, noting only that a percentage of employee, customer, and partner records had been exfiltrated. Because Craneware’s flagship software helps healthcare providers bill patients for services, it processes large amounts of medical records and patient data on behalf of its customers. This functionality means the breach potentially exposes sensitive health information, a risk that has been heightened by the company’s previous acquisition of Florida-based pharmacy software maker Sentry in 2021, which added 147 million patient records to its holdings.
Craneware CEO Keith Neilson did not immediately respond to inquiries regarding the incident or whether the hackers have made any ransom demands. It remains unclear whether the company’s systems are currently able to receive email amid the ongoing cyberattack. The lack of immediate detail on the specific data types stolen leaves the full impact on US healthcare providers undetermined at this stage.
This incident adds to a growing trend of cyberattacks targeting technology companies that supply services to the US healthcare sector. By compromising the software used to analyse billing processes, attackers can access vast amounts of patient medical data and attempt to extort companies with threats of public release. The vulnerability of these intermediaries has become a focal point for security concerns across the industry.
Craneware follows a series of high-profile breaches in the sector over the past year. In March, healthcare revenue tech firm TriZetto confirmed that hackers stole the personal and health data of more than 3.4 million people. That same month, medical data storage giant CareCloud reported a breach of electronic health records, though it has not disclosed the volume of data taken.
The pattern of attacks extends further back, with medical billing company Episource notifying at least 5.4 million people in July last year that their information had been stolen. The most significant incident occurred in 2024, when a Russian-speaking ransomware gang hacked UnitedHealth-owned Change Healthcare. That breach, attributed to the same group, resulted in the theft of medical and patient records for at least 192 million people, affecting a substantial proportion of the US population.
