A quiet but serious intrusion
On Monday, Craneware — a British software firm whose products run across more than 2,000 U.S. hospitals — told investors that attackers broke into its internal network and made off with employee and customer records. The company, headquartered in Edinburgh and listed on London’s AIM market, said it detected unauthorized access to a “subset” of its data environment and has since called in outside forensic investigators.
The breach has been reported to the FBI and to the UK’s Information Commissioner’s Office. Craneware said the intrusion is contained and the attackers no longer have access to its systems. Crucially, the company added that neither its own operations nor the services it provides to hospitals were disrupted.
But the details that remain unknown are troubling. Craneware did not say who was behind the attack, when the hackers first got in, how long they roamed the network, or whether a ransom was demanded. It also did not name any of the affected customers — and it did not say whether patient health information was among the stolen files.
What was taken — and what wasn’t
Craneware disclosed that a large number of file names were viewed and copied out of its network. Most of that material was non-sensitive or already publicly available regulatory data, the company said. But some employee data and customer and partner records were definitely taken.
The company said it is still working to determine the full scope of the theft and expects to notify affected organizations and individuals once it has a clearer picture. That timeline is vague, which is not unusual for breaches of this scale, but it leaves hospitals and their staff in an uncomfortable limbo.
The biggest open question: was patient data involved? If the stolen records include protected health information, the breach would trigger notification requirements under the U.S. Health Insurance Portability and Accountability Act (HIPAA). Craneware has not addressed that directly.
A sprawling target in healthcare IT
Craneware was founded in 1999 and sells billing, pricing and pharmacy software to American healthcare providers. The company says its tools are used by more than 2,000 hospitals and close to 10,000 clinics and retail pharmacies across the United States.
That makes it a juicy target. Healthcare vendors hold a goldmine of sensitive data — patient records, insurance details, billing information, employee credentials. And attackers know it. In recent years, hackers have repeatedly targeted the vendors that hospitals rely on, often with devastating results.
In March 2026, software firm CareCloud warned that patients’ electronic health records may have been leaked after hackers gained access to its systems. Two weeks before that, healthcare analytics firm Insightin told state regulators that 1.1 million people were affected by a data theft that happened in September 2025.
Those are not isolated incidents. In 2024, hackers breached healthcare technology company TriZetto Provider Solutions, exposing the data of 3 million people. Another 5 million were impacted when technology firm Episource was attacked. The pattern is clear: cybercriminals are going after the vendors, not just the hospitals themselves.
Why vendor breaches hit harder
When a single hospital gets hacked, it’s bad. But when a vendor like Craneware gets compromised, the blast radius is enormous. A single intrusion can ripple across thousands of hospitals and clinics, each one potentially exposed by the same weak link in the supply chain.
That’s why the FBI is involved. And it’s why regulators on both sides of the Atlantic are likely to scrutinize Craneware’s response closely. The company said it has engaged outside forensic investigators, but it has not disclosed which firm is handling the probe.
For the hospitals using Craneware’s software, the immediate priority is damage control. They need to know whether their patients’ data was stolen, and they need to know fast. For the rest of the healthcare industry, this breach is yet another reminder that healthcare cybersecurity is only as strong as the weakest vendor in the chain.
What comes next
Craneware said the attackers no longer have a foothold in its systems. That’s the good news. The bad news is that the data is already out — copied and likely sold or leaked. The company’s forensic investigation will take weeks, possibly months, to fully map what was taken.
Affected employees, customers and business partners will be notified once that work is done. But for now, the clock is ticking. Every day without answers is a day the stolen data could be used for phishing, identity theft or extortion.
This breach is a stark reminder that the software that keeps hospitals running is also a high-value target. And as long as attackers see healthcare vendors as a soft underbelly, the attacks will keep coming.