Sep 2, 2026 · 5 min read

A stock exchange announcement is not a breach notification

Craneware disclosed a breach to the London Stock Exchange. Your vendor disclosure venue is not the same thing as your notification clock.

Article header: A stock exchange announcement is not a breach notification

On July 20, 2026, Craneware plc published a Notice of Cyber Security Incident through the London Stock Exchange's Regulatory News Service. The company sells revenue-cycle software used by more than 2,000 US hospitals and roughly 10,000 clinics and pharmacies, and its own contact page puts its US headquarters in Deerfield Beach, Florida. The announcement says a significant volume of file names were viewed and exfiltrated, along with "a percentage of Craneware employee data as well as a subset of customer and partner records."

It also names who was told: the Information Commissioner's Office in the UK, and the FBI. Not HHS.

Two duties that look like one

An AIM-listed company discloses to the market because a price-sensitive event happened: the duty is owed to investors, triggered by materiality, discharged by publishing. A US healthcare notification duty is a different instrument end to end — triggered by a determination that unsecured protected health information was involved, owed to the covered entity and then to HHS, on its own clock. Satisfying the first does nothing for the second, and a hospital reading that RNS is reading a document written for a shareholder.

The wording repays slow reading. "File names were viewed and exfiltrated" is a narrower claim than file contents, and likely precise rather than evasive. But in a revenue-cycle system a file name routinely carries the client, a date range, and often the record type — so a file listing can be sensitive even when the files behind it were never opened. Then: "the current assessment is that a large element of the data involved is non-sensitive or already public regulatory data." That is a determination, made by the vendor, about the customer's data, before any customer has seen the file list.

What the HHS portal shows, and what it does not

HHS publishes every reported breach of unsecured PHI affecting 500 or more people. I pulled it on September 2, 2026: 729 entries in the current window, and Craneware is not one of them.

That is not evidence of a violation and should not be read as one. If no PHI was involved, nothing is required, and the company's own assessment points that way. A business associate also notifies the covered entity rather than HHS directly, with up to 60 days from discovery to do it. Craneware has published no discovery date, so the real deadline cannot be computed from outside. Measured from the RNS, 60 days runs to September 18.

Timeline titled The market announcement and the HIPAA window. Craneware published its RNS to the London Stock Exchange on July 20, 2026. As of September 2, 2026 — 44 days later — there is no Craneware entry in the HHS OCR breach portal. The HIPAA sixty-day business associate notification ceiling, measured from the RNS date because no discovery date was published, runs to September 18, 2026.

What it does show is the comparison. Three healthcare vendors breached in the same window appear as business associates with counts attached: CareCloud on July 24 at 3,756,469 people, Aesto on July 31 at 9,540,683, and Operation PAR — the Florida provider whose notification ran 380 days behind detection — on June 25 at 145,714. Each number exists because somebody finished a determination and filed it. Craneware customers have no number, because the determination that starts the clock is still the vendor's to make.

The practice: know the venue and the clause before you need them

Two things, both cheap, and both done in advance.

Write down where each vendor's disclosure would appear, and who is subscribed to it. For a listed company that is a regulatory feed — RNS for a UK or AIM issuer, EDGAR for an SEC registrant — not a status page, not the account manager. Both publish free email alerts keyed to a company name, about ten minutes each. The cost is not setup but maintenance: the list goes stale as vendors are acquired, re-domicile or delist, so it needs a look once a year or it becomes fiction.

Then read your own contract for the notification clause. The question is whether the clock starts at the vendor's discovery or its determination, and how many days it allows. HIPAA's 60 days is a ceiling, not a target, and a contract that simply restates the regulation has handed the vendor the maximum. Shortening it — 72 hours to a preliminary notice, the full determination to follow — is a renewal-cycle conversation, and vendors push back because it commits them to telling you things they do not yet understand. That is why the clause usually stays at 60 days.

If you cannot reopen the contract, ask for the artifact instead of the assurance. A vendor that has finished a forensic review can tell you which of your files appeared in the exfiltrated listing. "A large element was non-sensitive" is someone else's judgement about your data, and it is not the same as an answer.

What to check this week

  • For your five largest vendors holding regulated data: where would a breach disclosure appear, and is anyone subscribed to it?
  • Does each contract's notification clause start at discovery or at determination, and how many days does it allow?
  • If a vendor disclosed today, could you list which of your data sets sit in their environment?
  • Has any vendor told you an incident was "contained with no service disruption"? That describes availability, not confidentiality.
  • Who on your side decides whether a vendor's determination is good enough to rely on?

As of September 2, 2026, Craneware has published no initial access vector, intrusion date or detection date, and no update since July 20. It said the investigation was ongoing and that it would update the market as appropriate.


North InfoSec runs AI-assisted penetration testing and security assessments, including the third-party exposure review described above. northinfosec.com

← All articles