Major Healthcare Software Vendor Investigating Cyberattack – The HIPAA Journal
Major Healthcare Software Vendor Investigating Cyberattack
The healthcare technology company Craneware is investigating a cybersecurity incident and has confirmed that a significant amount of data was stolen in the attack, including some employee and customer data.
Craneware is a UK company that heavily targets U.S. healthcare companies. The company makes healthcare accounting and billing software, and partners with 2,000 hospitals and health systems, and around 10,000 pharmacies and clinics, many of which are located in the United States. According to the Craneware website, its software and Trisus cloud platform underpin around 165 million unique patient encounters and impact half a trillion healthcare dollars.
Craneware reports that the company quickly implemented its incident response plan and contained the incident, without any disruption to customer services or the company’s operations. The external investigators assisting with the response have not found any further signs of compromise, which indicates that the hackers have been ejected from its network.
While the review of the impacted data is still in the early stages, the company has confirmed that “a significant volume of file names were viewed and exfiltrated” by the hackers before they were ejected from its systems. “A percentage of Craneware employee data as well as a subset of customer and partner records have been accessed and exfiltrated,” explained the company in its cybersecurity incident notice. “The current assessment is that a large element of the data involved is non-sensitive or already public regulatory data.” The company has yet to confirm if any patient data was compromised in the incident.
The cyberattack has been reported to the UK’s data watchdog, the Information Commissioner’s Office (ICO), and the U.S. Federal Bureau of Investigation (FBI). The company has not yet disclosed the threat actor or group behind the attack, when access to its environment was gained, when the attack was discovered, or the names of affected customers.
“The company is continuing to assess the precise nature and scope of all the data involved and is working with its advisers to identify affected parties and prepare appropriate notifications, including any required further notifications to relevant authorities, in each case in accordance with applicable regulatory obligations,” explained the company.
There has been a spate of recent cyberattacks on healthcare vendors including software providers and medical device companies. Vendors often work with large numbers of healthcare clients and store or have access to large volumes of sensitive patient data, so they are attractive targets for hackers. It is currently unclear whether this was a data theft and extortion incident and if a ransom demand has been issued. No hacking group appears to have claimed responsibility for the attack.
The post Major Healthcare Software Vendor Investigating Cyberattack appeared first on The HIPAA Journal.
Protected in Name Only: HIPAA’s Health Data Gap Is Becoming a National Security Risk – Foundation for Defense of Democracies
ApolloMD Agrees to Pay $4.02M to Settle Data Breach Lawsuit
ApolloMD Business Services, a business associate that provides integrated, multispecialty physician, APC, and practice management services, has agreed to settle a class action lawsuit stemming from a May 2025 ransomware attack.
The attack was identified by ApolloMD on or around May 22, 2025, and the forensic investigation determined that a ransomware actor accessed its network between May 22 and May 23, 2025, potentially exfiltrating files containing the protected health information of patients of its healthcare provider clients. The Qilin ransomware group claimed responsibility for the attack.
The ApolloMD data breach included names, dates of birth, health information, health insurance information, and for some individuals, Social Security numbers, and was reported to the HHS’ Office for Civil Rights as affecting 626,540 individuals. The first batch of notification letters was mailed to the affected individuals starting in September 2025, with a second wave of notifications issued in March 2026.
The first class action lawsuits were filed shortly after the first round of notification letters were issued. In January 2026, the court granted the motion to consolidate the lawsuits into a single complaint – In re ApolloMD Data Breach Litigation – which was filed in the U.S. District Court for the Northern District of Georgia, Atlanta Division.
The consolidated lawsuit alleged that the ransomware attack occurred as a result of the failure of the defendant to implement reasonable and appropriate cybersecurity measures. ApolloMD denies all claims and contentions asserted in the action, including any wrongdoing and liability. Following mediation in January 2026, the parties agreed on the material terms of a settlement, which has now been finalized and has received preliminary approval from the court.
The defendant has agreed to establish a $4,020,000 settlement fund to pay benefits to the class members, after attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives have been deducted. All class members are entitled to a one-year membership to a CyEx medical data monitoring service and may claim one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member. Alternatively, a pro rata cash payment may be claimed, estimated at $75 per claimant. The cash payments will be subject to a pro rata increase or decrease depending on the number of claims received.
The deadline for objection and opting out is August 31, 2026. Claims must be submitted by September 30, 2026, and the final fairness hearing has been scheduled for October 5, 2026.
The post ApolloMD Agrees to Pay $4.02M to Settle Data Breach Lawsuit appeared first on The HIPAA Journal.
HHS Seeks Input on Potential Updates to the CLIA Regulations – The HIPAA Journal
HHS Seeks Input on Potential Updates to the CLIA Regulations
The HHS’ Centers for Medicare and Medicaid Services (CMS) and the Centers for Disease Control and Prevention (CDC) have issued a request for information (RFI) on potential updates to the Clinical Laboratory Improvement Amendments (CLIA) of 1988. The RFI covers several topics, including breath testing, laboratory processes and procedures, emergency preparedness, cybersecurity, and the use of artificial intelligence. The feedback received in response to the RFI will advise future actions and rulemaking. Comments are being accepted through September 14, 2026.
The CLIA regulations were enacted on October 31, 1988, strengthening federal oversight of clinical laboratories and helping to ensure the accuracy and reliability of patient test results. The CLIA regulations were promulgated in 1992, and while certain elements of the CLIA regulations have been updated over the years, a substantial update may be required to better reflect current knowledge and advancements in laboratory testing.
One area where updates may be required is cybersecurity, as threats across the healthcare sector have expanded significantly in both scope and severity. “As clinical laboratories increasingly rely on digital systems and connected technologies—such as Laboratory Information System (LIS), Electronic Health Record (EHR) integration, automated diagnostic devices, and virtual or remote access to laboratory and patient data—new cybersecurity risks have emerged,” explained the CMS and CDC in the RFI.
Many U.S. laboratories are HIPAA-regulated entities and must therefore comply with the requirements of the HIPAA Security Rule; however, there are gaps that need to be addressed and threats that the current HIPAA Security Rule does not adequately protect against. The CMS is seeking non-proprietary/non-confidential information on current laboratory cybersecurity practices and experiences related to protecting patient data and lab operations; user identity and access; remote access to systems containing personal information from overseas entities; restrictions on ports and/or internet protocol (IP) addresses; cybersecurity response plans; and cybersecurity training.
One area where further regulation is likely required is artificial intelligence, as the CLIA regulations were enacted long before AI tools started to be used in clinical settings. Model corruption, hallucinations, and compromises could have serious implications for the accuracy and reliability of testing. The CMS and CDC are seeking information on postanalytic interpretation and the use of AI tools, specifically, the algorithms and AI tools used in postanalytic analysis; the circumstances where software and AI tools are being used to interpret test results, histopathology slides, and results; the methods used to verify the performance of those tools; and whether there are any additional technology considerations for high complexity tests that the CMS and CDC should consider incorporating into the CLIA regulations.
The post HHS Seeks Input on Potential Updates to the CLIA Regulations appeared first on The HIPAA Journal.