U.K.-based billing software giant Craneware revealed it's been hit by a cyberattack where hackers made off with a "significant" volume of customer data, according to TechCrunch. The company has not disclosed exactly what that means.

Craneware's software processes billing, patient records, and medical data for thousands of American clinics, hospitals, and pharmacies serving millions of people. The company says hackers have been removed from its systems, though the investigation is ongoing.

TechCrunch reports that Craneware declined to specify what types of data were compromised beyond admitting that employee records, customer data, and partner information were exfiltrated. CEO Keith Neilson has not responded to questions about ransom demands.

When Craneware acquired pharmacy software maker Sentry in 2021, it inherited access to 147 million patient records accumulated over two decades. The scale of potential exposure from the current breach remains unclear.

Healthcare software companies have become prime targets for cyberattacks. According to the TechCrunch report, TriZetto confirmed a breach affecting 3.4 million people in March, while CareCloud reported a separate hit to its patient records storage. Last July, Episource notified 5.4 million people their data was stolen. The 2024 UnitedHealth-Change Healthcare ransomware attack compromised records for at least 192 million people.

When hackers target software providers rather than individual hospitals, they gain access across an entire ecosystem. One breach ripples through all users. Healthcare providers often pay ransoms because patient care obligations limit their options. Attackers use stolen data as leverage, threatening to publicly release sensitive medical information unless companies pay.

Craneware's vague statements and the CEO's silence suggest either the company is still assessing the damage or legal teams have imposed restrictions. Patients and providers need clarity on what was taken and who it affects.