X Rebuilds Android App from Scratch: What's New and Coming
X ships a rebuilt Android app after a year-long effort, promising faster performance and a foundation for rapid feature development.
Craneware data breach 2026: hackers stole customer data from the healthcare billing vendor used by thousands of US hospitals and pharmacies. Analysis of the incident and supply chain security lessons.
Learn about the Craneware data breach in 2026, where hackers stole customer data from the healthcare billing vendor used by thousands of US hospitals and pharmacies.
On July 20, 2026, U.K.-based healthcare billing software maker Craneware disclosed a cyberattack in which hackers stole a “significant volume” of customer data from its systems. The breach, announced via a regulatory filing with the London Stock Exchange, involved unauthorized access to a subset of its data environment and the exfiltration of employee data, customer data, and partner records. The company stated that hackers appear to have been expelled from its systems, but its investigation into the breach is ongoing.
Craneware’s flagship accounting and billing software is used by thousands of clinics, hospitals, and pharmacies across the United States. According to its website, more than 2,000 healthcare organizations and nearly 10,000 clinics and retail pharmacies rely on its products. This means the breach could have a significant downstream impact on the U.S. healthcare sector.
The company did not specify exactly what kinds of data were taken in the breach, only noting that a “percentage” of employee data, customer data, and partner records had been exfiltrated. In its regulatory filing, Craneware said, “The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data.” However, the company added that an investigation by internal IT staff and third-party cybersecurity firms was ongoing.
When Craneware acquired Florida-based pharmacy software maker Sentry in 2021, it gained access to the company’s 147 million patient records that had been collected over two decades. While Craneware did not confirm whether patient data was compromised in this breach, the scale of data the company handles makes the incident particularly concerning.
Craneware CEO Keith Neilson did not respond to questions about the incident, or if the hackers have contacted the company with any demands, such as a ransom. After publication, Craneware’s chief growth officer Ian Armstrong said the company was still investigating, but did not comment on the incident further. It is not yet clear if the company’s systems can receive email amid the ongoing cyberattack.
Although Craneware is a British company, its website heavily markets its products to American healthcare firms. It lists several U.S. trade associations and tech companies — including Microsoft and the National Rural Health Association — as strategic partners. This cross-border relationship highlights the interconnected nature of healthcare technology supply chains.
This breach is part of a pattern of supply-chain attacks targeting healthcare technology vendors. Last week, the security firm Fortified Health Security said supply-chain risk management was one of the sector’s biggest challenges. By compromising software that many healthcare providers use to analyze and understand their billing processes, hackers can access vast amounts of patient medical and health-related data, and extort the companies with threats of publicly releasing the information.
The Craneware incident serves as a stark reminder that healthcare organizations must scrutinize the security posture of their technology vendors. As the investigation continues, affected hospitals and pharmacies will be watching closely to understand the full scope of the data theft and whether patient information was exposed.
Continue exploring trending topics.
Google will begin carrying third-party app stores in Google Play starting July 22, 2026, following the withdrawal of the Epic settlement, opening new distribution channels for developers and easier access for users.