Craneware’s real problem is not outage. It is that a healthcare supplier can be breached, stay online, and still leak the records that tie hospitals, customers, and employees together. Standard availability-focused incident response would miss that downstream exposure.
The company says attackers got into a subset of its internal environment, copied a large number of file names, and took some employee data plus customer and partner records. Craneware says its services to more than 2,000 US hospitals were not disrupted, and it has contained the intrusion and brought in outside investigators.
That leaves the threat in the data, not the uptime. Even if the platform stays live, stolen vendor records can feed follow-on targeting of hospitals, partners, and staff across the healthcare supply chain.
US Hospital Finance Software Provider Craneware Reports Data Theft
Craneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theft
Software provider to more than 2,000 US hospitals says hackers stole employee and customer data
Craneware, which is headquartered in Edinburgh and listed on London's AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since brought in outside forensic investigators.