Craneware, a U.K.-based medical billing software maker, said on Monday it is responding to a cyberattack in which hackers stole “substantial amounts” of customer data from its systems.
In a statement to the London Stock Exchange, the company said the hackers appear to have been removed from the system, but the investigation into the breach continues.
Craneware's flagship accounting and billing software is used by thousands of clinics, hospitals, and pharmacies across the United States. The company did not say what type of data was exposed in the breach, only saying that “some” employee data, customer data and partner records were exposed.
The company develops software that helps healthcare providers bill patients for services, and processes large amounts of medical records and patient data on behalf of its customers. Craneware said when it acquired Florida-based pharmacy software maker Sentry in 2021, it gained access to 147 million patient records collected over 20 years.
Craneware CEO Keith Neilson did not immediately respond to TechCrunch's questions about the incident or whether the hackers had contacted the company with any ransom or other demands.
It is not yet clear whether the company's systems will be able to receive emails as the cyber attacks continue.
Although the details of the hack are still being investigated, it is the latest data breach in recent months, with hackers targeting high-tech companies that provide technology and services to the U.S. healthcare sector. By compromising the software that many healthcare providers use to analyze and understand the billing process, hackers can access vast amounts of patient medical and health-related data and blackmail companies with threats to release the information.
Craneware is the latest health technology giant to be breached in the past year.
Healthcare revenue technology company TriZetto admitted in March that hackers stole the personal and health data of more than 3.4 million people from its systems in a previous cyberattack. That very month, medical data storage giant CareCloud reported a breach of one of its stores storing electronic patient medical records, but it has not yet disclosed how much data was compromised.
Last July, medical billing company Episource began notifying at least 5.4 million people that their information had been stolen by hackers.
The largest breach of U.S. medical and healthcare data in history occurred in 2024, when a Russian-speaking ransomware group hacked UnitedHealth's Change Healthcare. The hackers stole the medical and patient records of at least 192 million people, and the company acknowledged that they affected a “significant percentage of people in the United States.”
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

