Craneware, whose software is used by hospitals and health systems across the U.S., disclosed a cybersecurity incident involving unauthorized access to a subset of its data environment.
The Edinburgh, Scotland-based company reported the incident in a July 20 filing with the London Stock Exchange. Craneware said it activated its incident response plan upon discovery, and its board appointed external cybersecurity and forensic specialists to investigate alongside the company’s internal IT team and retained security providers.
The incident has been contained, according to Craneware, and customer services and operations have not been disrupted. External specialists confirmed there are no residual indicators of compromise remaining in the company’s systems.
Investigators found that a significant volume of file names were viewed and exfiltrated. Craneware said its current assessment is that a large portion of that data is non-sensitive or already public regulatory information. A percentage of employee data and a subset of customer and partner records were also accessed and exfiltrated.
Craneware notified the U.K.’s Information Commissioner’s Office and the FBI in the U.S. The company said it is continuing to assess the full scope of the data involved and is working with advisers to identify affected parties and prepare required notifications, including any further disclosures to regulators.
Craneware sells billing, pricing and pharmacy software to American healthcare providers, working with more than 2,000 hospitals and close to 10,000 clinics and retail pharmacies.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.