Hospital software vendor Craneware’s ongoing assessment of this week’s cybersecurity event indicates that a “minority” of the patient records in its possession were affected, though the company says it cannot yet quantify the exact scope.
The company disclosed July 20 that unauthorized actors accessed and exfiltrated a subset of its data environment, including file names, employee data and a portion of customer and partner records. Craneware said the incident has been contained and there has been no disruption to customer services.
Craneware’s 2021 acquisition of pharmacy software company Sentry gave it access to an estimated 147 million patient records, according to TechCrunch. Ian Armstrong, Craneware’s chief growth officer, told Becker’s the data affected by the breach represents only a minority of that total, though the company said it cannot yet quantify the exact size of the affected subset. Mr. Armstrong said the compromised data came from internal servers unrelated to Craneware’s products, and that the company’s investigation into the incident’s scope is ongoing.
Craneware notified the U.K.’s Information Commissioner’s Office and the FBI following the incident and said it is working with advisers to identify affected parties. The company has not attributed the attack to a specific threat actor or disclosed an intrusion method.
Craneware’s software is used by more than 2,000 hospitals and nearly 10,000 clinics and retail pharmacies across the U.S.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.