Home
Blog
Craneware Group reports huge healthcare data breach, plays down risks

Craneware Group reports huge healthcare data breach, plays down risks

Paul Ducklin
07/21/2026
Share this article:

Breach reported in the US and the UK

Healthcare financial services provider Craneware has reported itself to the FBI in the US, and to the Information Commissioner’s Office (ICO) in the UK, over a cyberattack.

Craneware doesn’t directly provide health care such as nursing, doctoring, and actual treatment; instead it offers:

[A]pplications and [an] industry-leading team of experts [that] contextualize operational, financial, and clinical data, providing insights that clearly demonstrate realistic revenue integrity and 340B compliance opportunities for our customers.

In a document submitted to the London Stock Exchange (LSE), the company offers the curious admission that “a significant volume of file names were viewed and exfiltrated,” which at first reading makes it sound as though file contents (the data in the files themselves) were not stolen in the breach.

But the admission continues by saying that “a large element of the data involved is non-sensitive or already public regulatory data.”

This suggests that, in the breach, the attackers not only created a list of available file names, but also stole all the files on that list.

Remember that even non-sensitive data retained by a company for its own commercial benefit or regulatory compliance isn’t supposed to be accessible to outsiders at will.

And the disclosure statement continues by noting that “a percentage of Craneware employee data as well as a subset of customer and partner records have been accessed and exfiltrated.”

Simply put, although some of the stolen data might be considered “harmless” even though it’s now in the hands of cybercriminals, some of it sounds very personal and private indeed.

In this context, the words percentage and subset aren’t helpful, given that the percentage could be 100%, and in mathematical parlance, a set in its entirety is considered to be a subset of itself.

What to do?

  • As an individual, you may not know which providers of actual health care (such as doctors’ surgeries you have visited, hospitals that have treated you, or pharmacies that have supplied you with medication) share data about you with Craneware. If in doubt, check with the organizations or healthcare professionals you’ve dealt with recently.
  • If you are a user of Craneware products or services, keep your eyes open for forthcoming notifications that might affect you. Be prepared to pass on any bad news, your own findings, and your proposed response to any affected patients.
  • Whether you’re in healthcare or not, make sure you’ve planned for any disclosures you may be in the uncomfortable position of needing to publish in the future. Preparing for failure is not an admission that you intend to fail, and is much better than failing to prepare.
  • When penning a breach response, resist the temptation to invite your readers to infer that absence of evidence from the investigation you have done so far is evidence of absence of harm or risk.

Don’t forget, when talking about cyberattacks, that a breach of N critical records of personal information isn’t somehow mitigated just because 10N or even 100N non-personal and apparently “harmless” records were stolen at the same time.

After all, the cumulative damage caused by a breach can’t get smaller as the breach itself gets bigger!


Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!

Craneware Group reports huge healthcare data breach, plays down risks - SolCyber


More About Duck

Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!

Paul Ducklin
Paul Ducklin
07/21/2026
Share this article:

Table of contents:

The world doesn’t need another traditional MSSP 
or MDR or XDR.

What it requires is practicality and reason.

Related articles

Choose identity-first managed security.

We start with identity and end with transparency — protecting where attacks begin and keeping you informed, with as much visibility as you want. No black boxes, just clear, expert-driven security.
No more paying for useless bells and whistles.
No more time wasted on endless security alerts.
No more juggling multiple technologies and contracts.

Follow us!

Subscribe

Join our newsletter to stay up to date on features and releases.

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.

©
2026
SolCyber. All rights reserved
|
Made with
by
Jason Pittock

I am interested in
SolCyber DPM++

I am interested in
SolCyber XDR++™

I am interested in
SolCyber MDR++™

I am interested in
SolCyber Extended Coverage™

I am interested in
SolCyber Foundational Coverage™

I am interested in a
Free Demo

14588