Edinburgh-based Craneware disclosed a cyberattack that compromised customer data. The firm's software is used by thousands of US hospitals, pharmacies, and clinics for patient billing and healthcare operations.
Craneware, a healthcare software provider, confirmed that hackers stole a "significant" amount of data during a breach. The company did not immediately disclose the volume of records accessed or the specific nature of the compromised information.
The software serves a substantial portion of the US healthcare system, managing billing, payment processing, and patient data for hospitals, pharmacies, and clinics. This broad reach means the breach potentially affects millions of patient records.
The attack underscores ongoing vulnerabilities in healthcare infrastructure. Medical organizations face increasing pressure from cybercriminals targeting systems that process sensitive financial and health information. Hospitals and pharmacies are frequent targets because they often pay ransoms quickly to restore critical operations.
Craneware has not released details about when the breach occurred, how long attackers had access, or whether the stolen data included personally identifiable information, medical records, or payment details. The company is investigating the incident and working with customers and authorities.
The breach comes as healthcare cybersecurity remains a critical concern. The Health and Human Services Department has documented numerous significant breaches affecting healthcare providers in recent years, with impacts ranging from operational disruptions to compromised patient privacy.
Affected organizations are expected to notify patients as required by law, though notification requirements vary by state. Patients may face increased risk of identity theft or fraud if financial information was accessed.
Craneware faces potential regulatory scrutiny and lawsuits from affected customers and patients. The incident may also trigger investigations into the company's security practices and compliance with healthcare data protection standards.
Devices promising free movies are recruiting home internet connections into proxy networks without users' knowledge. The trade-off: your bandwidth and privacy.
QubesOS released a security update addressing a critical vulnerability that allows arbitrary code execution through an error reporting backchannel in the copy-to-VM function. The flaw affects multiple Qubes versions.
Android devices offer built-in protections against malicious apps, scam calls, and privacy breaches. Activating the correct security settings is essential to maximize these defenses.
File servers remain essential infrastructure for most organizations, but managing access permissions securely grows increasingly complex as systems expand. tenfold Software has outlined five best practices to simplify administration and enforce least-privilege access.