breach
Craneware breach hits vendor behind 2,000 US hospitals
2026-07-21

Craneware isn't a household name, but if you've ever been billed by an American hospital there's a fair chance its software was involved somewhere along the line. The Edinburgh-based firm sells billing, pricing and pharmacy systems to more than 2,000 US hospitals and close to 10,000 clinics and pharmacies. It is the sort of quiet plumbing company that most patients never hear of and most attackers absolutely have.
This week Craneware told investors that someone got into a subset of its data environment and took information on the way out. The company has called in outside forensic investigators, notified the FBI and Britain's Information Commissioner's Office, and says the intruders have been evicted. Its own operations kept running, and the services humming away inside hospitals were not disrupted.
What went missing
According to the notice, the attackers browsed and copied a lot of file names. Most of what they took was described as non-sensitive or already-public regulatory material. But some employee records went with them, along with data belonging to customers and partners. Craneware says it is still working out exactly who is affected and will notify the relevant organisations and individuals once that picture is clearer.
What Craneware isn't saying
The disclosure is notably thin on the details that usually decide how serious a breach turns out to be:
- It doesn't name the attackers or point at a known group.
- It doesn't say when the intruders first got in, or how long they had access.
- It doesn't mention a ransom demand, which by itself tells you very little either way.
- Critically, it doesn't say whether any patient data was involved.
That last point matters. If protected health information is in the mix, US health privacy law kicks in and the regulatory clock starts. If it isn't, this stays a corporate incident with an employee-records angle. Craneware, for now, is not committing either way.
Suppliers are the soft edge
Healthcare vendors have had a grim run of it. CareCloud warned in March that patient records may have leaked. Insightin told regulators an incident in September swept up 1.1 million people. TriZetto lost data on three million people in 2024. Episource lost five million.
Hospitals themselves have spent the last few years hardening up, forced along by ransomware crews shutting down emergency departments and cancelling surgeries. That work has paid off enough that attackers have started routing around it. Instead of hitting the hospital, they hit the company that handles the hospital's billing, or its patient portal, or its claims processing, and take the data from there. The pharmacy sits in the same pipe. So does the pricing engine. So does Craneware.
The interesting question isn't whether this pattern continues. It's how much of the American healthcare stack a determined attacker has to work through before they've been through most of it.