Healthcare software provider Craneware has confirmed that hackers accessed part of its internal environment and stole customer, employee, and partner data during a recently disclosed cyberattack. The Scotland-based company said the incident has been contained and has not disrupted its operations or the services it provides to thousands of healthcare organizations across the United States.
Craneware disclosed that unauthorized actors gained access to a subset of its data environment, where they viewed and exfiltrated a significant volume of file names and related records. According to the company’s preliminary investigation, much of the compromised information appears to consist of non-sensitive or publicly available regulatory data. However, the company also confirmed that a portion of employee records, along with some customer and partner information, was accessed during the breach. The exact categories of affected data are still being determined.
The company activated its incident response plan after discovering the intrusion and engaged external cybersecurity and digital forensics specialists to investigate the attack. Craneware said the experts have not identified any remaining indicators that the attackers continue to have access to its systems. It also stated that customer-facing services and the company’s cloud-based healthcare platform remained fully operational throughout the investigation.
Craneware develops financial management, compliance, and revenue cycle software used by approximately 2,000 hospitals and health systems, as well as roughly 10,000 clinics and pharmacies through its Trisus platform. Because the company processes operational and regulatory information for healthcare providers, investigators are continuing to determine whether any sensitive customer information was included in the compromised records. The company has not confirmed whether patient data was affected.
The company has notified the UK’s Information Commissioner’s Office (ICO), the U.S. Federal Bureau of Investigation (FBI), and other relevant authorities. Craneware said it will continue assessing the scope of the incident to determine whether additional regulatory notifications or communications with affected organizations are required. The investigation remains ongoing, and the company has not attributed the attack to a specific threat actor or disclosed how the attackers initially gained access to its network.
News of the breach triggered a decline in Craneware’s share price after the disclosure was made public. While the company emphasized that the incident has not affected business operations, investors reacted to the uncertainty surrounding the scope of the stolen data and the potential regulatory and legal consequences that could follow as the forensic investigation continues.
