DataBreachSearch.com
All cases
monitoring

Craneware Reports Data Breach in Oregon, Patient Data Exposed

Craneware, Inc., a healthcare technology provider, reported a data security incident to the Oregon Attorney General on September 14, 2026. The breach, which occurred on July 7, 2026, exposed sensitive patient data including names, birth dates, Social Security Numbers, and medical details. The company's investigation into the incident is ongoing and in a monitoring phase.

Compiled from official Attorney General recordsLast updated
State
Oregon
Breach date
July 7, 2026
Reported
September 14, 2026

What may have been exposed

  • Full Name
  • Date of Birth
  • Social Security Number
  • Medical Record Number
  • Health Insurance ID Number
  • Diagnosis and Treatment Information
  • Billing and Financial Account Details
  • Provider and Treatment Dates

Craneware, Inc. reported a data security incident to the Oregon Attorney General on September 14, 2026. This incident involved unauthorized access to its network environment, with the breach date identified as July 7, 2026. The company's filing indicates its investigation is currently in a monitoring status.

The types of sensitive personal data reported as exposed include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Billing and Financial Account Details, and Provider and Treatment Dates. These details originate from Craneware's role as a healthcare technology provider.

Exposure of such a combination of personal and medical identifiers can lead to various risks. Individuals whose data was compromised may face an increased risk of medical identity theft, where personal health information could be used to obtain medical services or file fraudulent insurance claims. There is also a heightened risk of financial fraud.

Individuals who receive a notification should review the information provided by Craneware, Inc. It is advisable to closely monitor explanations of benefits (EOBs) from health insurers and medical bills for any unfamiliar charges or services. Regularly reviewing credit reports for unusual activity is also a prudent step.

Activating fraud alerts with credit bureaus and being cautious of unsolicited communications requesting personal details can also help protect against potential misuse of exposed information. This public filing serves as official notification of the incident.

Source: Attorney General filing