Skip to content
Flash Briefing high Healthcare

Craneware Breach: Hackers Steal Data from UK Billing Software Firm Serving Thousands of US Hospitals

Craneware, a UK-headquartered company whose billing and financial analytics software serves thousands of United States hospitals and pharmacies, has confirmed a significant data theft. The company disclosed the breach via the London Stock Exchange on 20 July 2026, stating that attackers had accessed its systems and exfiltrated “a significant volume” of data including employee records, customer information, and partner records.

Craneware said it discovered the intrusion, contained it, and has expelled the threat actor from its environment. An investigation is underway with external forensic specialists. No ransom demands have been publicly confirmed. The initial access vector, dwell time, and whether any operational systems were disrupted beyond the data exfiltration have not been disclosed.

What’s at Stake

Craneware occupies a specific and sensitive position in US healthcare operations. The company provides billing optimisation, cost analytics, and revenue cycle management software used across thousands of clinics, hospitals, and pharmacies in the United States. Its products are deeply embedded in hospital financial workflows, which means the breach’s exposure extends beyond Craneware’s own employee and partner data to the question of what billing and integration data its systems hold on behalf of customers.

In 2021, Craneware acquired Sentry Data Systems, a Florida-based pharmacy analytics firm. Sentry’s platforms process pharmacy benefit management data across US healthcare networks, and its systems collectively handle information associated with approximately 147 million patient records. Whether Sentry-related data was included in the exfiltration has not been confirmed, but the acquisition substantially deepened Craneware’s data footprint. Healthcare providers with Sentry-facing integrations should treat this as an open question until Craneware provides more granular disclosure.

The Broader Pattern

This breach fits a sustained targeting pattern: financially motivated threat actors are consistently going after healthcare billing and revenue cycle software vendors rather than individual hospitals. The logic is straightforward. A single billing software vendor has integrations with hundreds or thousands of provider organisations, making it a high-yield target for data aggregation, credential harvesting, and downstream extortion.

The last two years have produced a concentration of such incidents. Change Healthcare’s 2024 ransomware attack affected an estimated 192 million Americans and paralysed US pharmacy operations for weeks. In 2026 alone, TriZetto (a healthcare payer software firm) reported 3.4 million records exposed in March and Episource disclosed 5.4 million records in a separate breach. CareCloud and several regional health system vendors have faced similar supply-chain-style compromises.

Craneware’s London Stock Exchange listing and the public disclosure indicate the company is treating the incident as material. The absence of a ransom demand claim or leak site posting is notable: this may still be in an active negotiation phase, or the threat actor may be operating with a different objective than immediate monetisation.

For US healthcare providers using Craneware or Sentry software:

  • Request formal written notification from Craneware on the scope of the exfiltration. Specifically: whether patient billing data, integration credentials, or records associated with Sentry acquisitions were included.
  • Audit API and integration credentials. Craneware’s billing software connects into hospital EHR, ERP, and payer systems. Verify that API keys, service account tokens, or credentials shared with Craneware cannot be used to access internal systems, and rotate any that may have been exposed.
  • Monitor for downstream fraud. Patient billing identifiers and healthcare account details in the exfiltrated data could support fraudulent insurance claims or enable targeted phishing against affected individuals.
  • Prepare independent breach notification assessment. Under HIPAA, if protected health information of US patients was included in the exfiltrated data, healthcare providers may have independent breach notification obligations regardless of Craneware’s own disclosure timeline. Do not wait for Craneware to notify.

The investigation is at an early stage. Craneware has not publicly identified the threat actor or the method of intrusion. Further updates are expected as the forensic investigation progresses.