Craneware Discloses Data Breach Affecting Software Used by Thousands of U.S. Healthcare Providers

Craneware, the Edinburgh-based healthcare billing software company whose products serve thousands of U.S. hospitals, clinics, and pharmacies, disclosed a cyberattack on July 20, 2026 in which hackers exfiltrated what the company described as a "significant volume" of data TechCrunch.
The disclosure was filed as a formal statement with the London Stock Exchange, fulfilling Craneware's regulatory obligation to inform investors of material events. In the statement, the company confirmed that a "percentage" of employee data, customer data, and partner records were taken during the breach. Craneware did not specify exactly what kinds of data were involved TechCrunch.
The hackers appear to have been expelled from Craneware's systems, though the investigation remains ongoing. No further technical details regarding the attack vector (the method used to break in), dwell time (how long the attackers were inside before being detected), or threat actor attribution (which group is responsible) have been disclosed at this stage TechCrunch.
Craneware CEO Keith Neilson did not immediately respond to TechCrunch's questions about the incident or whether hackers made any demands such as a ransom TechCrunch.
The market reaction was swift. Craneware shares fell as much as 8.9% in early trading on the Monday following the disclosure and closed over 7% down Insurance Business Mag Investing.com.
The scope of potential exposure extends well beyond Craneware's direct corporate operations. The company acquired Florida-based pharmacy software maker Sentry in 2021, a transaction that gave Craneware access to 147 million patient records collected over two decades TechCrunch. Whether any of those records were among the exfiltrated data has not been confirmed. Craneware's flagship accounting and billing software is used by thousands of clinics, hospitals, and pharmacies across the United States, making the downstream blast radius of this breach difficult to assess until the company clarifies the specific data categories involved TechCrunch.
The absence of detail on data types is notable. In healthcare-sector breaches, the distinction between billing metadata, clinical records, and personally identifiable information determines the regulatory reporting obligations under HIPAA (the U.S. health privacy law) and the severity of downstream harm to affected individuals. Craneware's statement does not yet draw those lines, leaving affected institutions unable to assess their own exposure or begin breach-notification workflows. For the thousands of U.S. healthcare providers that depend on Craneware's platform for revenue cycle management — the process of tracking patient care from registration through final payment — the lack of specificity also complicates their own compliance posture. Under HIPAA's Breach Notification Rule, covered entities have 60 days to notify affected individuals once a breach is identified, but that clock cannot meaningfully start without knowing what was taken.
The broader context here is that this incident fits a structural pattern we have seen before. A U.K.-listed company operating critical healthcare billing infrastructure for U.S. providers sits at an intersection of regulatory regimes, and incidents of this kind test the seams between U.K. investor-disclosure obligations and U.S. healthcare-data protection law. The London Stock Exchange filing prioritized shareholder communication; the U.S. healthcare providers dependent on Craneware's software will need answers oriented toward patient-data obligations, and the timelines for those two tracks do not necessarily align.
The investigation is ongoing, and further detail on the specific data categories affected, the attack methodology, and any ransom demands may emerge as Craneware completes its forensic review.


