Veradigm warns of patient data breach after ransomware gang claims attack

Veradigm Faces Patient Data Breach After Ransomware Gang Claims Attack

Healthcare technology company Veradigm has disclosed a data breach affecting thousands of its customers, including hospitals and clinics across the United States. The breach is attributed to a ransomware gang that claims to have stolen sensitive patient information, including Social Security numbers and personal details.

According to a filing with the US Securities and Exchange Commission (SEC), an attacker obtained credentials from one of Veradigm’s third-party vendors through a compromised API reserved for customer services. This allowed the threat actor to copy patient data without being detected by the company’s security measures. The stolen information includes names, home addresses, Social Security numbers, email addresses, phone numbers, and personally identifiable guarantors.

Veradigm emphasizes that clinical or medical information remained safe in this incident, but acknowledges that the breach has affected a small number of customers. The company has initiated its incident-response procedures, notified law enforcement, and is currently investigating to determine the scope of the breach. Affected customers and individuals are being notified, with credit-monitoring services offered where applicable.

The ransomware gang behind the attack, known as The Gentlemen, has claimed responsibility for the intrusion on September 5 and listed Veradigm on its data leak site. The group alleges to be holding 3.5 million patient records and threatens to leak the stolen data by Friday, September 11, unless a ransom payment is negotiated.

The Gentlemen emerged in mid-2025 as a double-extortion group, combining data theft with data encryption on various systems, including Windows, Linux, NAS, BSD, and ESXi. Its modus operandi involves opportunistic attacks that rely only on access availability, making it difficult for companies to detect and prevent such incidents.

The breach highlights the ongoing threat posed by ransomware gangs to healthcare organizations and their customers. Once attackers have valid credentials, security measures can be bypassed, allowing them to copy sensitive data without being detected. This emphasizes the need for robust incident-response procedures and regular security audits to identify vulnerabilities in third-party vendors’ systems.

As a result of this breach, Veradigm is taking steps to strengthen its security posture and protect against similar incidents in the future. For individuals affected by the breach, it’s essential to remain vigilant and take proactive measures to protect their sensitive information. This includes monitoring credit reports for any suspicious activity and considering credit-monitoring services to prevent identity theft.

The incident serves as a reminder that even with robust security measures in place, companies can still fall victim to sophisticated attacks. It underscores the importance of continuous security awareness, regular audits, and incident-response planning to mitigate the impact of such breaches.


Source: Bleeping Computer — 2026-09-09