Craneware, a British software company whose billing and pharmacy products are used by more than 2,000 US hospitals and nearly 10,000 clinics, has confirmed hackers broke into its internal network and stole employee and customer data.
The Edinburgh-based company told investors it detected unauthorized access to a subset of its data environment and has brought in outside forensic investigators. Craneware has reported the incident to the FBI and Britain’s Information Commissioner’s Office.
Craneware said the intrusion has been contained and that attackers no longer have a foothold in its systems. Neither its own operations nor the services it provides to hospitals were disrupted. The company confirmed that a large number of file names were viewed and copied, including some employee data and customer and partner records.
It remains unclear whether patient information was among the stolen data, a determination that would dictate whether US health privacy rules apply. Craneware said it is still working to identify exactly what was stolen and expects to notify affected organizations once complete.
The breach follows a pattern of hackers targeting healthcare technology vendors. Recent incidents have hit CareCloud, Insightin, TriZetto Provider Solutions, and Episource, collectively exposing data on millions of patients.
