A cybersecurity incident involving Craneware has exposed employee information and records connected to customers and business partners, raising concerns involving a healthcare software provider serving more than 2,000 U.S. hospitals and health systems and nearly 10,000 clinics and retail pharmacies.
Craneware, a British healthcare software provider headquartered in Edinburgh, confirmed that an unauthorized party gained access to a portion of its internal data environment. The company disclosed the incident through a regulatory announcement issued on Monday, July 20.
The company activated its incident-response plan and appointed external cybersecurity and forensic specialists to investigate the intrusion. Those specialists are working alongside Craneware’s internal information-technology team and retained cybersecurity providers to determine how the attack occurred, what systems were accessed, and what information was removed.
Craneware said the intrusion has been contained. External investigators reported finding no remaining indicators of compromise associated with the incident inside the company’s systems.
Customer services and Craneware’s internal operations were not disrupted, according to the company. Hospitals, clinics, and pharmacies using its software were able to continue accessing the services provided through Craneware’s platforms.
The absence of an operational shutdown does not mean the incident was limited to an unsuccessful intrusion. Craneware confirmed that information was accessed and removed from its environment.
Investigators determined that a significant volume of file names was viewed and exfiltrated. Craneware’s initial assessment found that a large portion of the material was either non-sensitive or consisted of regulatory data already available to the public.
The exposed information also included a percentage of Craneware employee data and a subset of customer and business-partner records. The company has not disclosed how many employees, customers, partners, or individual records were affected.
Craneware has not confirmed whether the compromised customer records contained patient information, protected health information, medical records, billing details, prescription information, insurance data, Social Security numbers, financial information, login credentials, or other personally identifiable information.
That distinction will be critical in determining the notification requirements that apply in the United States. A breach involving unsecured protected health information can trigger obligations under federal health-privacy rules, including notification to affected individuals and reporting to the U.S. Department of Health and Human Services.
The company is examining the precise nature and scope of the exposed information before issuing notifications. Craneware said it is working with its advisers to identify affected parties and prepare notices required under applicable regulatory obligations.
Craneware has notified the FBI in the United States and the Information Commissioner’s Office in the United Kingdom. Additional notifications could follow as investigators determine which organizations, jurisdictions, and categories of information were involved.
The company has not publicly identified the attackers or disclosed when they initially entered its environment. It has also not revealed how long the unauthorized access continued before detection.
No initial-access method has been announced. It remains unknown whether the intrusion involved stolen credentials, an exploited software vulnerability, phishing, compromised third-party access, or another technique.
Craneware has not reported receiving a ransom or extortion demand. No cybercriminal organization has been officially identified as responsible, and the company has not classified the incident as ransomware.
The investigation remains active, leaving several central questions unresolved. The number of records taken, the sensitivity of the information, the affected customers, the intrusion timeline, and the possibility of patient-data exposure have not been publicly established.
Founded in 1999, Craneware develops financial-performance software for healthcare organizations. Its products support hospital billing, pricing, pharmacy operations, revenue management, compliance, and other administrative functions.
The company is publicly traded on the London Stock Exchange’s Alternative Investment Market under the symbol CRW. Its business is centered heavily on the American healthcare sector despite being headquartered in Scotland.
Craneware reports working with more than 2,000 hospitals and health systems and supporting nearly 10,000 clinics and retail pharmacies. That reach gives the incident potential significance far beyond the company’s internal workforce, although the number of healthcare organizations directly affected by the exposed records remains unknown.
The breach also demonstrates the broader security risk created when healthcare organizations depend on centralized software and service providers. A compromise affecting one vendor can expose information connected to numerous hospitals, clinics, pharmacies, insurers, employees, and business partners without requiring attackers to breach each organization separately.
Healthcare vendors remain valuable targets because their systems can contain large collections of operational, financial, employment, insurance, and medical information. The sensitivity of that information can make it useful for identity theft, fraud, account compromise, extortion, and targeted social-engineering attacks.
Other healthcare technology companies have disclosed major data-security incidents affecting large numbers of people. CareCloud warned in March that patient electronic health-record information may have been exposed following unauthorized access to its systems.
Healthcare analytics company Insightin Health reported a data-theft incident affecting approximately 1.1 million people after unauthorized activity occurred in September 2025.
A breach involving TriZetto Provider Solutions affected approximately 3 million people, while a separate incident involving healthcare technology company Episource exposed information connected to approximately 6.7 million individuals.
Those incidents are separate from the Craneware investigation and do not establish that the same attackers, methods, or categories of data were involved. They demonstrate the scale of exposure that can result when a healthcare technology provider holding information for numerous organizations is compromised.
Craneware’s statement that services remained operational is significant for continuity of care and hospital administration. The company has not reported interruptions to billing, pharmacy management, pricing systems, or other customer services.
The primary confirmed impact at this stage is data confidentiality rather than operational availability. Information was accessed and exfiltrated, but the company has not reported that software services were encrypted, disabled, or manipulated.
Affected organizations and individuals cannot yet determine their exposure because Craneware has not completed its review or issued a full accounting of the stolen information. Notifications are expected after the company identifies the records involved and determines which parties must be contacted.
Craneware said it will provide additional market updates as appropriate. Until that investigation is complete, claims concerning patient-data exposure, the number of victims, attacker attribution, ransomware involvement, or an extortion demand would remain unconfirmed.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



