trampolim.net
PT EN

Trampolim · Technology weekly

The Week in Tech

Issue 12Week of July 13–19, 202616 stories
Security

Healthcare software supplier breached, and the reach is two thousand hospitals

Craneware disclosed unauthorised access to part of its data environment. Its platform serves thousands of hospitals, clinics and pharmacies.

Healthcare software supplier breached, and the reach is two thousand hospitals
Security · July 13–19, 2026

Craneware, the Scottish healthcare financial software firm, disclosed to the London Stock Exchange on July 20 an incident involving unauthorised access to part of its data environment. Its platform serves roughly two thousand US hospitals and nearly ten thousand clinics and pharmacies.

The client count is what gives the case its scale. This isn't one compromised organisation, it's a supplier sitting inside the financial operations of thousands of them. Contracting third-party software means inheriting its attack surface, and that rarely appears in any individual hospital's risk assessment.

The data type makes it worse. Healthcare financial software processes billing information, which means procedure, associated diagnosis and patient identity. That isn't data you rotate like a password.

The pattern repeated across the period in other incidents in the sector, with campaigns aimed at widely used corporate platforms. The attacker's logic is economic: compromising one supplier yields access to many clients at once.

For buyers, the practical lesson isn't to stop using specialist suppliers, but to ask beforehand what usually gets asked afterwards: what data of ours does the supplier hold, for how long, and how are we told when something happens.

Book a call