Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies
Craneware, a healthcare billing software provider serving thousands of U.S. hospitals and pharmacies, suffered a significant data breach compromising employee, customer, and partner records including potentially 147 million patient records acquired through a prior acquisition. This incident exemplifies a critical vulnerability in healthcare IT supply chains, where compromised vendor software can expose vast amounts of sensitive patient data across the entire customer base and enable ransomware extortion campaigns. Healthcare organizations face mounting supply chain security risks, as evidenced by recent breaches at TriZetto, CareCloud, Episource, and Change Healthcare, requiring immediate reassessment of vendor security controls and data access privileges.
