The healthcare billing software creator is currently responding to a cyberattack affecting US healthcare providers.
What happened
The Craneware Group, a leading UK-owned software company that provides cloud-based revenue, financial, and operational software specifically to US healthcare companies, recently announced they experienced a data breach.
Although Craneware is a British-owned company that operates out of Edinburgh, Scotland, and has offices in Poland and England, its technology helps US hospitals and pharmacies manage revenue and maintain federal compliance with regulations like HIPAA. Because of their deep connection to the US, it’s believed this breach will mostly, if not only, impact the US hospitals and healthcare systems Craneware works with.
In a report filed with the London Stock Exchange, as required under British law, Craneware said that an investigation has revealed that a “significant volume of file names were viewed and exfiltrated.” No information about the specific type of data or the number of impacted individuals has been provided.
Going deeper
In the report, filed on July 20th, 2026, Craneware said the incident has now been contained and that their “incident response plan has been activated.” There were no disruptions to service and Craneware doesn’t believe there is any indication that additional security issues could arise. Since the company does business in the US, they have also notified the FBI. While limited information about the data has been released, Craneware did share, “A percentage of Craneware employee data as well as a subset of customer and partner records have been accessed and exfiltrated.”
In the know
According to TechCrunch, Craneware’s flagship accounting and billing software, Trisus, is “used by thousands of clinics, hospitals, and pharmacies across the United States.”
Since the company provides billing services for patients, they handle troves of medical records and patient records. For instance, Craneware bought Florida-based pharmacy software maker, Sentry, in 2021, which gained them access to 147 million patient records that had been collected by Sentry over a two-decade period.
Why it matters
Even though Craneware is based in the United Kingdom, the breach still has ramifications for the US and beyond, showing that global technology can bring about innovative solutions but also substantially increase risks.
In recent months, this isn’t the only attack on large vendors that work closely with the US. In June 2026, Paubox reported on a breach impacting Tata, a key component supplier for Apple products. The attack was carried out by ransomware gang WorldLeaks, which demanded a ransom payment to return and not sell the stolen data. Ultimately, the data was posted on the dark web.
As attacks like these hit suppliers or vendors, they can be even more troubling to resolve and recover from, because these vendors often work with multiple companies. By impacting multiple hospital networks, as in this case, the breach more effectively gathers data and scares victims. For the patients of these healthcare centers or hospitals, the breach also increases confusion, as victims may not even realize Craneware had their data in the first place.
FAQs
Why would a British-owned company focus on the US?
The decision to focus on the US is a strategic and financial one. Craneware chooses to work in the US because of its unique and complex healthcare structure. The organization believes they can help add value to the US healthcare sector, and their revenue shows the business is currently overall successful.
Is it possible that every medical record held by Craneware was accessed?
Craneware holds millions of medical records, and while it’s possible that the majority of these records were accessed, it’s by no means certain. Many organizations hold different sets of data on different servers. For instance, since Craneware works with many different healthcare organizations, it’s possible that each or some organizations have their data held on a separate server. The true number of victims will likely be released in the near future.
Will US victims be notified?
Yes, either Craneware or, if they agree to, their healthcare partners, will ultimately be required to notify victims. Even when an organization is based outside of the US, if they have clients in the US, they must comply with HIPAA. Despite the requirement, actually notifying patients can be a lengthy and time-consuming process, so victims will likely have to wait some time before they are notified.
