Scottish health-technology firm Craneware reported a data exposure, adding to a run of incidents affecting the healthcare technology supply chain. Health data is among the most sensitive there is, which makes any exposure especially serious.
The takeaway
Healthcare and the suppliers around it are squarely in attackers’ sights: the data is valuable, the services are critical, and budgets are often stretched. It’s the same pressure we see across hospices, clinics and care providers.
Protecting health data well is achievable on a realistic budget with the right priorities — access control, encryption, monitoring and staff awareness. It’s work we do regularly with healthcare and charity clients, including through initiatives like our recent hospice cyber resilience summit.
Why healthcare data is in the crosshairs
Health information is among the most sensitive and valuable data there is: it cannot be reset like a password, it commands a high price on criminal markets, and the services that depend on it are genuinely critical. The suppliers around healthcare — software firms, billing and analytics providers, managed IT partners — are increasingly targeted because they aggregate data from many organisations at once. For NHS-connected bodies and their suppliers, obligations such as the Data Security and Protection Toolkit raise the bar further, and stretched budgets make the challenge harder still.
Proportionate protection on a real budget
Strong protection of health data is achievable without enterprise spending if the priorities are right: tight access control so people only see what they need, encryption of data at rest and in transit, multi-factor authentication, monitoring to catch misuse early, and regular staff awareness training. Tested backups and a clear incident plan round it out. This is the same pressure we see across hospices, clinics and care providers, and it is work we do regularly — including through our Charity & Hospice Cyber Protection package and initiatives like our recent hospice cyber-resilience summit.
Source: ITPro, 20 July 2026.