Dormant Medium impact Data breach Checked 1w ago

Craneware healthcare software vendor data breach

Craneware, a UK based maker of billing and financial software used by thousands of US hospitals and pharmacies, confirmed hackers broke into part of its systems and stole a significant volume of data. Stolen data included employee records, customer and partner information, and file names, but the company says the intrusion was contained and customer services were not disrupted. No attacker has been named and no evidence has emerged that patient care systems were affected.

Started
Jul 20, 2026
Latest activity
Jul 22, 2026
Attributed to
Not confirmedNo credible attribution yet
Where
United States, United Kingdom
Sectors
Healthcare, Technology
Scale
Craneware software is used by roughly 2,000 hospitals and health systems and about 10,000 pharmacies and clinics, mostly in the US, though

Current status

No credible public update has appeared since Craneware's July 22, 2026 disclosure about the affected records.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Impact

Attackers accessed and exfiltrated a significant volume of data from Craneware's own environment, including employee records and some customer and partner data, but Craneware says the breach did not disrupt its software or customer operations. The company later said the exposed data came from internal servers unrelated to its actual products, and that only a minority of the patient records it holds through its 2021 Sentry acquisition were affected, though it still cannot say exactly how many.

What to do

Hospitals and pharmacies that use Craneware's Trisus platform should watch for a direct notification from Craneware about whether their data was involved.

Timeline

  1. Sep 5, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Jul 22, 2026

    Craneware's chief growth officer Ian Armstrong told Becker's Hospital Review that the data affected by the breach represents only a minority of the roughly 147 million patient records tied to its 2021 Sentry pharmacy acquisition, and that the compromised data came from internal servers unrelated to Craneware's actual products; the company still could not quantify the exact scope.

    Containedbeckershospitalreview.com
  3. Jul 21, 2026

    Reporting confirmed Craneware's software underpins billing and financial operations for roughly 2,000 hospitals and health systems and about 10,000 pharmacies and clinics, mostly in the US.

    Containedhipaajournal.com
  4. Jul 20, 2026

    Craneware said it had already expelled the attackers and activated its incident response plan, with no disruption to customer services or business operations.

    Containedtechcrunch.com
  5. Jul 20, 2026

    Craneware disclosed to the London Stock Exchange that hackers gained unauthorized access to part of its data environment and stole a significant volume of data, including file names, employee data, and some customer and partner records.

    Emergingtechcrunch.com

Sources

Related reports