Craneware, a healthcare technology company headquartered in Edinburgh and listed on London's AIM market, has disclosed a data breach affecting more than 2,000 hospitals across the United States. The company detected unauthorized access to a subset of its data environment and immediately notified investors of the security incident.
Craneware provides revenue cycle management and value analysis software to healthcare organizations, making it a critical vendor for hospital financial operations. The company's client base includes a significant portion of US hospitals, which rely on its platforms to manage billing, pricing, and cost optimization processes.
The company has retained external forensic investigators to determine the scope of the breach and identify what data may have been accessed or exfiltrated. Craneware has not yet disclosed the nature of the unauthorized access, whether it involved ransomware, or what specific types of data were potentially compromised. The investigation is ongoing, and the company has not provided a timeline for when affected hospitals will receive detailed information about their exposure.
The breach poses significant risks given the sensitive nature of healthcare data and the operational importance of revenue cycle systems. Hospitals affected by the incident may face potential exposure of patient billing information, employee data, or operational details depending on what systems were accessed. The scale of the breach, affecting thousands of healthcare facilities, makes it one of the more significant healthcare vendor incidents in recent months.
Healthcare organizations using Craneware services should prepare for potential data exposure notifications and review their vendor risk management protocols. Affected hospitals should monitor for signs of data misuse, prepare incident response procedures, and maintain communication with Craneware for updates. Organizations should also assess their contractual obligations regarding breach notification to patients and regulatory bodies if protected health information was involved.
Source: https://therecord.media/software-provider-for-us-hospitals-customer-data-breach


