U.K.-based healthcare billing software maker Craneware is responding to a cyberattack in which hackers stole a “significant volume” of customer data from its systems, the company said on Monday.
The company said the hackers appear to have been expelled from its systems, but its investigation into the breach is ongoing, according to a statement filed with the London Stock Exchange .
Craneware’s flagship accounting and billing software is used by thousands of clinics, hospitals, and pharmacies across the United States. The company did not say exactly what kinds of data were taken in the breach, only noting that a “percentage” of employee data, customer data, and partner records had been exfiltrated.
The company, whose software helps healthcare providers bill patients for services, handles large amounts of medical records and patient data on behalf of its customers. When it bought Florida-based pharmacy software maker Sentry in 2021, Craneware said it gained access to the company’s 147 million patient records that had been collected over two decades.
Craneware CEO Keith Neilson did not immediately respond to TechCrunch’s questions about the incident, or if the hackers have contacted the company with any demands, such as a ransom.
It’s not yet clear if the company’s systems can receive email amid the ongoing cyberattack.
While details of the hack are still under investigation, this is the latest data breach in recent months where hackers have targeted tech companies that supply tech and services to the U.S. healthcare sector. By compromising software that many healthcare providers use to analyze and understand their billing processes, hackers can access vast amounts of patient medical and health-related data, and extort the companies with threats of publicly releasing the information.
Craneware is the latest health tech giant to be breached in the past year.
In March, healthcare revenue tech firm TriZetto confirmed hackers stole more than 3.4 million people’s personal and health data from its systems during an earlier cyberattack. That very month, medical data storage giant CareCloud reported a breach of one of its stores of patients’ electronic health records , but has not yet said how much data was taken.
Last July, medical billing company Episource began notifying at least 5.4 million people that their information had been stolen by hackers.
The largest ever breach of U.S. medical and healthcare data occurred in 2024, when a Russian-speaking ransomware gang hacked UnitedHealth-owned Change Healthcare. The hackers stole the medical and patient records of at least 192 million people , which the company conceded affected a “substantial proportion of people in America.”