Craneware healthcare software vendor data breach
Craneware, a UK based maker of billing and financial software used by thousands of US hospitals and pharmacies, confirmed hackers broke into part of its systems and stole a significant volume of data. Stolen data included employee records, customer and partner information, and file names, but the company says the intrusion was contained and customer services were not disrupted. No attacker has been named and no evidence has emerged that patient care systems were affected.
- Started
- Jul 20, 2026
- Latest activity
- Jul 22, 2026
- Attributed to
- Not confirmedNo credible attribution yet
- Where
- United States, United Kingdom
- Sectors
- Healthcare, Technology
- Scale
- Craneware software is used by roughly 2,000 hospitals and health systems and about 10,000 pharmacies and clinics, mostly in the US, though
Current status
No credible public update has appeared since Craneware's July 22, 2026 disclosure about the affected records.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Impact
Attackers accessed and exfiltrated a significant volume of data from Craneware's own environment, including employee records and some customer and partner data, but Craneware says the breach did not disrupt its software or customer operations. The company later said the exposed data came from internal servers unrelated to its actual products, and that only a minority of the patient records it holds through its 2021 Sentry acquisition were affected, though it still cannot say exactly how many.
What to do
Hospitals and pharmacies that use Craneware's Trisus platform should watch for a direct notification from Craneware about whether their data was involved.
Timeline
-
Sep 5, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Jul 22, 2026
Craneware's chief growth officer Ian Armstrong told Becker's Hospital Review that the data affected by the breach represents only a minority of the roughly 147 million patient records tied to its 2021 Sentry pharmacy acquisition, and that the compromised data came from internal servers unrelated to Craneware's actual products; the company still could not quantify the exact scope.
Containedbeckershospitalreview.com -
Jul 21, 2026
Reporting confirmed Craneware's software underpins billing and financial operations for roughly 2,000 hospitals and health systems and about 10,000 pharmacies and clinics, mostly in the US.
Containedhipaajournal.com -
Jul 20, 2026
Craneware said it had already expelled the attackers and activated its incident response plan, with no disruption to customer services or business operations.
Containedtechcrunch.com -
Jul 20, 2026
Craneware disclosed to the London Stock Exchange that hackers gained unauthorized access to part of its data environment and stole a significant volume of data, including file names, employee data, and some customer and partner records.
Emergingtechcrunch.com
Sources
- Hackers stole 'significant' amount of data from tech firm relied on by thousands of US hospitals and pharmacies TechCrunch Jul 20, 2026
- Major Healthcare Software Vendor Investigating Cyberattack The HIPAA Journal Jul 21, 2026
- Craneware breach exposes employee and customer data Cyber Security News Jun 30, 2026
- Craneware data breach exposes employee records The Cyber Express Jul 15, 2026
- Hackers steal customer data from major hospital software vendor Cybersecurity Dive Jul 21, 2026 unverified
- Craneware says cybersecurity incident affected only a 'minority' of patient records Becker's Hospital Review Jul 22, 2026 unverified
- US Hospital Finance Software Provider Craneware Reports Data Theft Infosecurity Magazine Jul 21, 2026
Related reports
- Craneware data breach exposes employee records Jul 15, 2026
- Craneware breach exposes employee and customer data Jun 30, 2026