Hospital software vendor Craneware’s ongoing assessment of this week’s cybersecurity event has raised new questions about the scope of the breach, though the company still has not confirmed whether patient data was compromised.
The company disclosed July 20 that unauthorized actors accessed and exfiltrated a subset of its data environment, including file names, employee data and a portion of customer and partner records. Craneware said the incident has been contained and there has been no disruption to customer services.
Since the initial disclosure, reporting from TechCrunch and The Record has highlighted the potential scale of the exposure. Craneware’s 2021 acquisition of pharmacy software company Sentry gave it access to an estimated 147 million patient records, according to TechCrunch. The Record reported that Craneware has not said whether patient information specifically was among the data taken, leaving that question open as the company continues its investigation.
Craneware notified the U.K.’s Information Commissioner’s Office and the FBI following the incident and said it is working with advisers to identify affected parties. The company has not attributed the attack to a specific threat actor or disclosed an intrusion method.
Craneware’s software is used by more than 2,000 hospitals and nearly 10,000 clinics and retail pharmacies across the U.S.
Editor’s note: Becker’s has reached out to Craneware for comment on the scope of the breach and will update this story with any response.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.