:

HOSPITAL SOFTWARE FIRM BREACHED, PATIENT DATA AT RISK

SECURITY DESK2 MIN READ
MON, JUL 20, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Edinburgh-based Craneware disclosed a cyberattack that compromised customer data. The firm's software is used by thousands of US hospitals, pharmacies, and clinics for patient billing and healthcare operations.

Craneware, a healthcare software provider, confirmed that hackers stole a "significant" amount of data during a breach. The company did not immediately disclose the volume of records accessed or the specific nature of the compromised information. The software serves a substantial portion of the US healthcare system, managing billing, payment processing, and patient data for hospitals, pharmacies, and clinics. This broad reach means the breach potentially affects millions of patient records. The attack underscores ongoing vulnerabilities in healthcare infrastructure. Medical organizations face increasing pressure from cybercriminals targeting systems that process sensitive financial and health information. Hospitals and pharmacies are frequent targets because they often pay ransoms quickly to restore critical operations. Craneware has not released details about when the breach occurred, how long attackers had access, or whether the stolen data included personally identifiable information, medical records, or payment details. The company is investigating the incident and working with customers and authorities. The breach comes as healthcare cybersecurity remains a critical concern. The Health and Human Services Department has documented numerous significant breaches affecting healthcare providers in recent years, with impacts ranging from operational disruptions to compromised patient privacy. Affected organizations are expected to notify patients as required by law, though notification requirements vary by state. Patients may face increased risk of identity theft or fraud if financial information was accessed. Craneware faces potential regulatory scrutiny and lawsuits from affected customers and patients. The incident may also trigger investigations into the company's security practices and compliance with healthcare data protection standards.

■ SOURCES

TechCrunch

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The FCC is preparing to use its newly granted power to retroactively ban previously approved DJI gadgets imported into the United States. The action targets suspected front companies created to circumvent the foreign drone ban on the Chinese manufacturer.

JUST NOWIndustry Desk

Flock Safety, a major license plate recognition camera company, has repeatedly provided misleading information to city councils, police departments, and the public, according to an ACLU investigation. The findings raise questions about the accuracy of claims made by the surveillance technology provider.

JUST NOWIndustry Desk

Prophet Security released a practical framework for assessing AI SOC platforms, helping organizations evaluate solutions based on real-world performance rather than controlled demonstrations.

5H AGOAI Desk

Hackers are actively exploiting vulnerable WordPress installations to compromise websites, according to multiple cybersecurity firms. WordPress released patches for two critical security flaws last week.

6H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.