Craneware, a UK‑based healthcare billing software maker, suffered a data breach that exposed customer and employee data used by hospitals and pharmacies across the US.

Craneware, a UK‑based provider of healthcare billing software, confirmed a data breach that exposed both customer and employee information used by thousands of hospitals and pharmacies across the United States.

Scope of the breach

The intrusion, discovered in early July, affected the company’s cloud‑based platform that stores billing records, payment histories, and staff credentials. While Craneware has not disclosed exact numbers, it described the loss as “significant” and said the data included names, email addresses, and hashed passwords of healthcare providers and their employees.

Impact on hospitals and pharmacies

Hospitals and pharmacy chains that rely on Craneware’s software to process insurance claims and manage revenue cycles may now need to reset passwords and monitor for phishing attempts. The breach could also complicate compliance with HIPAA regulations, prompting internal audits and potential reporting to state health agencies.

Company response

Craneware’s security team engaged a third‑party forensic firm, isolated the compromised servers, and began notifying affected clients. The firm urged customers to enable multi‑factor authentication and to review any unusual account activity.

  • Reset passwords for all user accounts
  • Activate multi‑factor authentication where possible
  • Monitor network traffic for suspicious logins
  • Report any anomalies to Craneware’s security hotline

Regulators are expected to evaluate whether the breach constitutes a reportable incident under the Health Information Technology for Economic and Clinical Health (HITECH) Act, which could result in fines if remediation steps are deemed insufficient.

The incident underscores the growing risk faced by third‑party vendors that handle sensitive health‑care data, a concern that has risen sharply as cyber‑criminals target the sector’s interconnected ecosystems.

For more details, see the TechCrunch coverage of the Craneware breach.