← All stories
● Covered by 4 sources · 15 reportsMedium impact13 negative

Craneware Reports Data Breach Affecting US Hospitals and Pharmacies

🔄 Updated 2d ago — new reporting from The Record
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Craneware reported a data breach affecting US hospitals and pharmacies.
  • Hackers accessed employee, customer, and partner data.
  • The incident involved a 'significant volume' of data theft.
  • Craneware's operations and services remain undisrupted.
  • Investigations by external experts and authorities are continuing.
  • CareCloud confirmed 3.75 million patient records were stolen.
  • The breach is the fifth-largest health data theft in 2026.
  • CareCloud detailed the breach in a filing with HHS on Monday.
  • The number of affected victims was revised up on Tuesday.
  • Hackers accessed data in a cloud storage environment over six days.
  • SickKids Hospital announced a cybersecurity incident.
  • The breach exposed data of current and former employees and job applicants.
  • The incident stemmed from a flaw in third-party software.
  • SickKids' public-facing Careers website was temporarily pulled offline.
  • Clinical systems and patient records were untouched.
  • SickKids Hospital released a statement on Thursday.
  • The incident is the second cyberattack on SickKids since 2022.
  • The incident also affected employees of related organizations, including the SickKids Foundation.
  • Nutex Health disclosed a cyberattack.
  • Nutex Health filed the cyberattack with the SEC.
  • Nutex Health operates 28 facilities across 12 states.
  • Paylogix disclosed a cyberattack.
  • Hackers stole financial and health data from Paylogix.
  • The Paylogix incident occurred in November.
  • The Paylogix breach affected tens of thousands of individuals.
  • The Akira ransomware group is suspected in the Paylogix attack.
  • Paylogix notified state regulators.
  • Class-action lawsuits are being organized against Paylogix.
  • Hackers stole files from Paylogix's network between November 13 and November 18.
  • Stolen Paylogix data includes Social Security numbers, financial, and health information.
  • Federal law enforcement was notified of the Paylogix incident.
  • Nutex Health is a healthcare management and operations company.
  • Nutex Health operates micro-hospitals, specialty hospitals, and outpatient departments.
  • Nutex Health does not believe the breach will materially impact its business.
  • McKesson disclosed a cybersecurity incident.
  • ShinyHunters claimed responsibility for the McKesson breach.
  • ShinyHunters claimed to steal 284 million patient records from McKesson.
  • ShinyHunters used vishing attacks on employees to breach McKesson.
  • McKesson discovered the incident on August 25, 2026.
  • McKesson disclosed the incident in a Form 8-K filing with the SEC.
  • McKesson provides medicines, medical supplies, technology, and services.
  • ShinyHunters set a September 1 deadline for ransom negotiations.
  • The breach affected customers in McKesson's Oncology & Multispecialty and Medical-Surgical business units.
  • McKesson's services were not affected by the incident.
  • McKesson offers complimentary credit monitoring.
  • McKesson confirmed the breach on Friday.
  • McKesson expected intermittent service degradation.
  • McKesson's CTO Francisco Fraga sent a notice to customers.
  • ShinyHunters used phishing and social engineering to access McKesson's network.
  • Nutex Health confirmed patient, employee, provider, business, and financial information was stolen.
  • The Gentlemen ransomware group claimed responsibility for the Nutex Health breach.
  • The Gentlemen ransomware group threatened to leak Nutex Health data.
  • A class-action complaint was filed against Nutex Health in Texas.
  • Nutex Health is facing extortion demands from attackers.
  • Nutex Health earned $427.2 million in the first half of 2026.
  • Nutex Health operates 27 facilities.
  • Nutex Health initially disclosed the cyberattack on August 24.

Data Breach Overview

Craneware, a UK-based healthcare software provider serving over 2,000 US hospitals and pharmacies, announced that a data breach had occurred. This cyberattack resulted in the theft of employee, customer, and partner data, though the specifics of the stolen information are still under investigation.

Impact on Healthcare Services

Craneware provides vital billing and patient management software to healthcare providers. Despite the breach, Craneware confirmed that its operations and service delivery to hospitals and pharmacies were not disrupted.

Authorities Involved

The data breach has been reported to the FBI and the UK's Information Commissioner’s Office. Craneware is working with external forensic experts to ascertain the extent and impact of the breach. Hackers have been removed from the system, but investigations are ongoing.

Background and Data Concerns

Craneware's acquisition of pharmacy software maker Sentry in 2021 expanded its access to a massive database of 147 million patient records. While it's not confirmed if patient data was involved, the fact that Craneware manages sensitive information heightens the incident's potential impact.

Concluding Remarks

Craneware continues to assess the breach's impact while ensuring the integrity of its services. The industry is closely monitoring the situation due to the sensitive nature of healthcare data involved.

Updates

🕒 2026-09-01 · new reporting from The Record
  • Nutex Health is facing extortion demands from attackers.
  • Nutex Health earned $427.2 million in the first half of 2026.
  • Nutex Health operates 27 facilities.
  • Nutex Health initially disclosed the cyberattack on August 24.
🕒 2026-09-01 · new reporting from SecurityWeek
  • Nutex Health confirmed patient, employee, provider, business, and financial information was stolen.
  • The Gentlemen ransomware group claimed responsibility for the Nutex Health breach.
  • The Gentlemen ransomware group threatened to leak Nutex Health data.
  • A class-action complaint was filed against Nutex Health in Texas.
🕒 2026-08-31 · new reporting from TechCrunch
  • McKesson confirmed the breach on Friday.
  • McKesson expected intermittent service degradation.
  • McKesson's CTO Francisco Fraga sent a notice to customers.
  • ShinyHunters used phishing and social engineering to access McKesson's network.
🕒 2026-08-31 · new reporting from SecurityWeek
  • ShinyHunters set a September 1 deadline for ransom negotiations.
  • The breach affected customers in McKesson's Oncology & Multispecialty and Medical-Surgical business units.
  • McKesson's services were not affected by the incident.
  • McKesson offers complimentary credit monitoring.
🕒 2026-08-29 · new reporting from BleepingComputer
  • McKesson disclosed a cybersecurity incident.
  • ShinyHunters claimed responsibility for the McKesson breach.
  • ShinyHunters claimed to steal 284 million patient records from McKesson.
  • ShinyHunters used vishing attacks on employees to breach McKesson.
  • McKesson discovered the incident on August 25, 2026.
  • McKesson disclosed the incident in a Form 8-K filing with the SEC.
  • McKesson provides medicines, medical supplies, technology, and services.
🕒 2026-08-26 · new reporting from SecurityWeek
  • Nutex Health is a healthcare management and operations company.
  • Nutex Health operates micro-hospitals, specialty hospitals, and outpatient departments.
  • Nutex Health does not believe the breach will materially impact its business.
🕒 2026-08-25 · new reporting from The Record
  • Paylogix disclosed a cyberattack.
  • Hackers stole financial and health data from Paylogix.
  • The Paylogix incident occurred in November.
  • The Paylogix breach affected tens of thousands of individuals.
  • The Akira ransomware group is suspected in the Paylogix attack.
  • Paylogix notified state regulators.
  • Class-action lawsuits are being organized against Paylogix.
  • Hackers stole files from Paylogix's network between November 13 and November 18.
  • Stolen Paylogix data includes Social Security numbers, financial, and health information.
  • Federal law enforcement was notified of the Paylogix incident.
🕒 2026-08-25 · new reporting from BleepingComputer
  • Nutex Health disclosed a cyberattack.
  • Nutex Health filed the cyberattack with the SEC.
  • Nutex Health operates 28 facilities across 12 states.
🕒 2026-08-21 · new reporting from The Record
  • SickKids Hospital released a statement on Thursday.
  • The incident is the second cyberattack on SickKids since 2022.
  • The incident also affected employees of related organizations, including the SickKids Foundation.
🕒 2026-08-21 · new reporting from BleepingComputer
  • SickKids Hospital announced a cybersecurity incident.
  • The breach exposed data of current and former employees and job applicants.
  • The incident stemmed from a flaw in third-party software.
  • SickKids' public-facing Careers website was temporarily pulled offline.
  • Clinical systems and patient records were untouched.
🕒 2026-08-19 · new reporting from TechCrunch
  • CareCloud confirmed 3.75 million patient records were stolen.
  • The breach is the fifth-largest health data theft in 2026.
  • CareCloud detailed the breach in a filing with HHS on Monday.
  • The number of affected victims was revised up on Tuesday.
  • Hackers accessed data in a cloud storage environment over six days.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~23 min · 21 stories · Sep 03

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Healthcare facilities operator Nutex disclosed that patient and employee data were stolen during a cyberattack in August, with the company now facing extortion demands from the attackers. This incident impacts a healthcare provider operating 27 facilities across 12 states and highlights ongoing data security challenges in the healthcare sector.

Nutex Health confirmed a data breach where personal and business information was stolen, with the Gentlemen ransomware group claiming responsibility and threatening to leak the data. This incident highlights ongoing cybersecurity risks for healthcare providers and the increasing threat of data exfiltration by ransomware groups.

The ShinyHunters hacking group claims responsibility for a cyberattack on McKesson, a major U.S. pharmaceutical distributor, resulting in the exfiltration of millions of patient and employee records from cloud-hosted environments. This incident highlights ongoing vulnerabilities in healthcare data security and the effectiveness of social engineering tactics used by hacking groups.

Healthcare giant McKesson Corporation confirmed that the ShinyHunters extortion group exfiltrated customer data from its systems, with a deadline of September 1 for ransom negotiations. The breach affects a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units, potentially compromising sensitive health and personal information.

McKesson, a major healthcare and pharmaceutical distributor, disclosed a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration. The ShinyHunters extortion group claims responsibility, stating they stole 284 million patient data records through vishing attacks on employees. This incident impacts a critical healthcare infrastructure provider and potentially exposes a large volume of sensitive patient data.

Nutex Health, a healthcare management company, reported unauthorized access to its network, resulting in the exfiltration of files that may contain confidential or private information. The company is investigating the scope of the breach, which could involve patient, employee, and operational data, and acknowledged the possibility of stolen data being leaked.

Employee benefits platform Paylogix disclosed a cyberattack that occurred in November, resulting in the theft of financial and health data belonging to tens of thousands of individuals. The incident, suspected to be linked to the Akira ransomware group, has led to notifications to state regulators and the organization of class-action lawsuits.

Hospital operator Nutex Health disclosed a cyberattack where an unauthorized third party exfiltrated data from its servers, including potentially private or confidential information. The company is investigating the scope of the breach and has engaged cybersecurity specialists and law enforcement.

Canada's Hospital for Sick Children (SickKids) experienced a cybersecurity incident that exposed personal information of current and former employees, job applicants, and staff from related organizations. This incident, believed to be linked to a third-party software application, marks the second cyberattack on the hospital since a 2022 ransomware event, highlighting ongoing vulnerabilities in healthcare sector cybersecurity.

The Hospital for Sick Children (SickKids) announced a cybersecurity incident that exposed personal information of current and former employees, as well as job applicants, due to a flaw in third-party software. This breach highlights the ongoing vulnerability of organizations to supply chain attacks and the sensitive nature of data collected through job application portals.

CareCloud, a health data company, confirmed that a March data breach exposed the personal and medical records of over 3.7 million patients. This incident is the fifth-largest health data theft reported in 2026 so far, highlighting ongoing vulnerabilities in healthcare data security.

The ransomware group "The Gentlemen" hijacked the Facebook page of AnMed, a nonprofit medical system, posting ransom demands and claims of exfiltrated data two weeks after an initial cyberattack. AnMed removed the unauthorized content and is investigating the incident, which has kept 10 facilities closed.

CareCloud, a U.S. health tech company, is notifying hundreds of thousands of individuals that their medical records were stolen in a cyberattack earlier this year. Hackers accessed one of its electronic health record data stores for six days in March, compromising sensitive personal and financial information for at least 345,000 people, with the number expected to rise.

Craneware, a UK-based healthcare software provider, reported a cyberattack resulting in the theft of a significant volume of customer data. The breach impacts numerous U.S. hospitals and pharmacies that rely on Craneware's services for billing and patient records management.

Craneware, a software provider for over 2,000 U.S. hospitals, revealed a data breach where hackers accessed employee and customer information. They reported the incident to the FBI and reported that while some compromised data was non-sensitive, the exact details remain unclear, raising concerns about patient data privacy.