Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Craneware, Software Vendor Behind 2,000 US Hospitals' Billing Systems, Confirms Data Theft

Craneware, a Scottish company whose billing and accounting software runs behind the scenes at roughly 2,000 US hospitals and health systems and nearly 10,000 clinics and pharmacies, told investors on Monday that hackers broke into its systems and stole a significant volume of data.
The disclosure came in a regulatory filing with the London Stock Exchange, where Craneware trades on the Alternative Investment Market. The company said hackers accessed and exfiltrated a large number of file names, along with a percentage of employee data and a subset of customer and partner records, according to the filing reported by the Press Association and TechCrunch.
Craneware says the intruders have been kicked out of its systems, but the investigation is ongoing. The company has notified the UK's Information Commissioner's Office and the FBI, and it's working with outside cybersecurity firms and advisers to nail down exactly what was taken, according to the Press Association.
What Craneware is claiming, and what it isn't
Craneware's own language downplays the severity: "The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data," the company said. It also says the breach hasn't disrupted customer services or operations, and there's no sign the intruders compromised its live systems beyond the data theft itself.
Craneware did not specify what kinds of sensitive data, if any, were among the stolen files, and CEO Keith Neilson did not respond to questions from TechCrunch about whether hackers have made ransom demands. TechCrunch also reported it's unclear if Craneware's systems can currently receive email amid the incident.
Craneware isn't a small player. The company's flagship platform, Trisus, handles billing analytics for a huge slice of the US healthcare system. When Craneware bought Florida-based pharmacy software maker Sentry in 2021, it inherited access to 147 million patient records built up over two decades, according to TechCrunch. Whether any of that legacy data sits in the systems that were breached is one of the open questions Craneware's investigation still has to answer.
A pattern, not an isolated incident
Craneware is the fourth major healthcare-adjacent tech vendor to disclose a breach in roughly the past year. TriZetto confirmed in March that hackers stole personal and health data belonging to more than 3.4 million people. That same month, medical records storage firm CareCloud disclosed a breach of patient electronic health records but has not said how much data was taken. Medical billing company Episource began notifying at least 5.4 million people last July that hackers had stolen their information.
None of those come close to the 2024 breach of UnitedHealth-owned Change Healthcare, still the largest healthcare data breach in US history. A Russian-speaking ransomware gang stole medical and patient records belonging to at least 192 million people, an incident UnitedHealth itself acknowledged affected a substantial share of the American population.
Hackers increasingly target the software vendors that sit behind hospitals and clinics rather than the providers themselves. Compromise one billing platform and you potentially get a pipeline into patient data across thousands of downstream customers at once. Security firm Fortified Health Security said in a report last week that healthcare providers identified six times more supply-chain risks in the first half of 2026 than in the same period of 2025, with nearly two-thirds of those risks rated critical or high-severity, according to Cybersecurity Dive.
What's still unknown
Craneware has not said how the hackers got in, how long they had access before being detected, or whether any group has claimed responsibility or demanded ransom. The company also hasn't said how many of its roughly 2,000 hospital and health-system customers, or 10,000 clinics and pharmacies, might have had data touched by the intrusion.
Until Craneware's investigation wraps up and it notifies affected parties directly, hospitals and pharmacies relying on Trisus are left waiting to find out whether their own billing and patient data was among the files taken. The FBI and the UK's Information Commissioner's Office have both been looped in, but neither agency has announced an independent investigation or findings of its own. The next concrete marker to watch for is whether Craneware issues direct breach notifications to specific customers, which would indicate the scope has moved from company-wide file exfiltration to identifiable patient or provider records.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.