Vendor Breach Exposes Hospital Relationship Data

Craneware’s real problem is not outage. It is that a healthcare supplier can be breached, stay online, and still leak the records that tie hospitals, customers, and employees together. Standard availability-focused incident response would miss that downstream exposure. The company says attackers got into a subset of its internal environment, copied a large number of file names, and took some employee data plus customer and partner records. Craneware says its services to more than 2,000 US hospitals were not disrupted, and it has contained the intrusion and brought in outside investigators. That leaves the threat in the data, not the uptime. Even if the platform stays live, stolen vendor records can feed follow-on targeting of hospitals, partners, and staff across the healthcare supply chain.

Part of the PlainSec briefing for 2026-07-22

Sources