Overview
- In a July 20 London Stock Exchange filing, Craneware disclosed unauthorized access to a subset of its data environment and said investigators found a significant volume of file names were viewed and exfiltrated.
- The company said a percentage of employee records and a subset of customer and partner files were accessed and taken during the incident.
- Craneware activated its incident response plan, engaged external cybersecurity and forensic specialists, and reported the breach contained with no disruption to customer services and no residual indicators of compromise found so far.
- The firm has notified the U.K. Information Commissioner’s Office and the U.S. FBI, and markets reacted with shares falling in early trading as analysts warned that any confirmation of sensitive U.S. patient data would drive regulatory and legal fallout.
- Because Craneware supplies billing and pharmacy software to more than 2,000 hospitals and roughly 10,000 clinics and pharmacies, investigators’ next findings on whether downstream patient records were exposed will determine potential fines, notifications to affected parties, and wider risks to health providers.