
UK healthcare software provider Craneware is investigating a cyberattack in which hackers accessed part of its data environment and stole a significant volume of files. The company said the incident has been contained, with no disruption reported to customer services or its wider operations.
Craneware has not confirmed whether patient medical records were among the compromised information. Its investigation is continuing with support from external cybersecurity and forensic specialists.
Customer and Employee Records Affected
According to Craneware’s official regulatory announcement, the attackers gained unauthorised access to a subset of the company’s systems. A percentage of employee, customer and partner data was viewed and removed.
Initial findings indicate that a large proportion of the affected material may consist of non-sensitive information or publicly available regulatory data. Craneware has not disclosed when the intrusion began, how the attackers entered its systems or whether it received a ransom demand.
The company said the hackers appeared to have been removed from its environment. It has notified relevant regulators, law-enforcement agencies, the UK Information Commissioner’s Office and the US Federal Bureau of Investigation.
Software Used Across US Healthcare Sector
Craneware develops billing, revenue-management and pharmacy software for hospitals, clinics and pharmacies in the United States. Its Trisus platform is used by about 40% of registered US hospitals, alongside thousands of clinics and retail pharmacies.
The company expanded its access to healthcare data after purchasing Florida-based Sentry Data Systems for $400 million in 2021. At the time, the acquisition was reported to include access to around 147 million patient records collected over 17 years.
Craneware has not said whether data linked to Sentry or its patient-record holdings was accessed. It said affected customers, partners and employees would be contacted as the investigation establishes the type and scope of information involved.
Healthcare Suppliers Face Continued Attacks
Healthcare technology providers can hold information from multiple hospitals and medical organisations within shared systems. A breach at one supplier can therefore expose records connected to several healthcare customers.
Craneware said its systems remain operational and customer services have continued without interruption. The company has not provided a timeline for completing its forensic review or releasing further details about the stolen files.
Featured image credits: Magnific.com
For more stories like it, click the +Follow button at the top of this page to follow us.
