Edinburgh-based healthcare software firm Craneware confirmed July 20 that hackers accessed its corporate network and exfiltrated employee records, customer files, and partner data, much of which was non-sensitive, from a central system supporting financial operations at more than 2,000 U.S. hospitals, clinics, and pharmacies.
Craneware disclosed the incident in a regulatory filing with the London Stock Exchange. “A significant volume of file names were viewed and exfiltrated,” the company stated. The intrusion has been contained and customer-facing services remain operational.
“The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data,” Craneware stated. “A percentage of Craneware employee data as well as a subset of customer and partner records have been accessed and exfiltrated.”
The company said it has notified the FBI and Britain’s Information Commissioner’s Office (ICO) and retained outside forensic investigators. The precise volume of affected records has not been determined.
Craneware’s Trisus platform, built on Microsoft Azure, serves as the primary revenue intelligence tool for a significant share of the U.S. hospital market.
The company reported $184 million in annual recurring revenue as of fiscal year 2025, with roughly 90% drawn from long-term subscription relationships, making it a high-value, deeply embedded target.
No threat actor has publicly claimed responsibility. It remains unknown whether ransomware was deployed.
The breach follows the February 2024 attack on Change Healthcare, an Optum subsidiary, which exposed data on an estimated 190 million individuals and demonstrated the systemic risk posed by centralized healthcare software vendors.
The investigation is ongoing.






