Technology

Hackers Stole Data from a Company That Helps Thousands of U.S. Hospitals Get Paid

Martin HollowayPublished 2w ago3 min readBased on 5 sources
Reading level
Hackers Stole Data from a Company That Helps Thousands of U.S. Hospitals Get Paid

Craneware, a company based in Edinburgh, Scotland, makes billing software used by thousands of U.S. hospitals, clinics, and pharmacies. On July 20, 2026, Craneware announced that hackers had broken into its systems and stolen what the company called a "significant volume" of data TechCrunch.

The announcement was filed as a formal statement with the London Stock Exchange, where Craneware's shares are traded. Companies listed there are required to tell investors about major events. Craneware confirmed that a portion of its employee data, customer data, and partner records was taken. The company did not say exactly what kinds of data were involved TechCrunch.

The hackers appear to have been removed from Craneware's systems, though the investigation is still ongoing. The company has not shared details about how the attackers got in, how long they were inside, or who was responsible TechCrunch.

Craneware CEO Keith Neilson did not immediately respond to questions about the incident or whether the hackers demanded a ransom TechCrunch.

Investors reacted quickly. Craneware shares fell as much as 8.9% in early trading the Monday after the announcement and closed over 7% down Insurance Business Mag Investing.com.

The potential impact goes beyond Craneware itself. In 2021, the company bought a Florida-based pharmacy software company called Sentry, which gave Craneware access to 147 million patient records collected over twenty years TechCrunch. It is not yet confirmed whether any of those records were taken. Because Craneware's software is used by thousands of healthcare providers across the United States, it is hard to know how far the damage reaches until the company says exactly what was stolen TechCrunch.

The lack of detail about what kind of data was taken matters. In healthcare, there is a big difference between billing information, medical records, and personal details like names and addresses. That difference determines what the law requires under HIPAA, the U.S. law that protects health information. Under HIPAA, hospitals and other providers must notify affected patients within 60 days of discovering a breach. But they cannot start that clock without knowing what was actually taken.

The broader context here is that this situation reveals a gap between two different sets of rules. Craneware is a U.K. company, so its first obligation was to inform its shareholders through the London Stock Exchange. But the hospitals and pharmacies that use its software operate under U.S. healthcare law, which is focused on protecting patient data. Those two priorities do not always move on the same timeline, and the people whose data may be at risk are left waiting.

The investigation is ongoing. More details about what data was taken, how the attack happened, and whether any ransom was demanded may come out as Craneware finishes its review.