The healthcare technology company Craneware is investigating a cybersecurity incident and has confirmed that a significant amount of data was stolen in the attack, including some employee and customer data. Craneware is a UK company that heavily targets U. S.
healthcare companies. The company makes healthcare accounting and billing software, and partners with 2,000 hospitals and health systems, and around 10,000 pharmacies and clinics, many of which are located in the United States. According to the Craneware website, its software and Trisus cloud platform underpin around 165 million unique patient encounters and impact half a trillion healthcare dollars.
Craneware reports that the company quickly implemented its incident response plan and contained the incident, without any disruption to customer services or the company’s operations. The external investigators assisting with the response have not found any further signs of compromise, which indicates that the hackers have been ejected from its network. While the review of the impacted data is still in the early stages, the company has confirmed that “a significant volume of file names were viewed and exfiltrated” by the hackers before they were ejected from its systems.
“A percentage of Craneware employee data as well as a subset of customer and partner records have been accessed and exfiltrated,” explained the company in its cybersecurity incident notice. “The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data.” The company has yet to confirm if any patient data was compromised in the incident.
The cyberattack has been reported to the UK’s data watchdog, the Information Commissioner’s Office (ICO), and the U. S. Federal Bureau of Investigation (FBI).
The company has not yet disclosed the threat actor or group behind the attack, when access to its environment was gained, when the attack was discovered, or the names of affected customers. “The company is continuing to assess the precise nature and scope of all the data involved and is working with its advisers to identify affected parties and prepare appropriate notifications, including any required further notifications to relevant authorities, in each case in accordance with applicable regulatory obligations,” explained the company.
There has been a spate of recent cyberattacks on healthcare vendors including software providers and medical device companies. Vendors often work with large numbers of healthcare clients and store or have access to large volumes of sensitive patient data, so they are attractive targets for hackers. It is currently unclear whether this was a data theft and extortion incident and if a ransom demand has been issued.
No hacking group appears to have claimed responsibility for the attack. The post Major Healthcare Software Vendor Investigating Cyberattack appeared first on The HIPAA Journal .
Originally published at hipaajournal.com