Veradigm has disclosed a patient data breach after a cybersecurity incident at one of its third-party vendors exposed sensitive information for thousands of individuals. The company, which supplies electronic health records and other software to medical practices across the United States, says the breach did not disrupt operations but affected a small number of customers.
The incident occurred when an attacker obtained credentials from a vendor’s environment that granted access to Veradigm’s API reserved for customer services. This allowed the threat actor to copy patient data, which included personal details and Social Security numbers (SSNs) for some patients. Fortunately, clinical or medical information remained safe.
It’s worth noting that the breach did not involve direct access to Veradigm’s broader network, servers, databases, or other systems. The company attributes this limited access to the specific vendor’s compromised credentials and the restricted interface used by the attacker. After discovering the breach, Veradigm initiated its incident-response procedures, notified law enforcement, and is currently investigating to determine the scope.
The Gentlemen ransomware gang has claimed responsibility for the attack, listing 3.5 million patient records on its data leak site. The threat actor alleges that these records include full names, home addresses, SSNs, email addresses, phone numbers, and personally identifiable information or guarantors. In a statement, The Gentlemen threatens to leak the stolen data by Friday, September 11, unless Veradigm engages in ransom payment negotiations.
The breach highlights the importance of robust cybersecurity measures for third-party vendors. With thousands of hospitals, clinics, and biopharmaceutical firms relying on Veradigm’s solutions, even a small number of affected customers is cause for concern. The incident also underscores the growing threat posed by double-extortion groups like The Gentlemen, which combine data theft with data encryption.
As cybersecurity threats continue to evolve, it’s essential for organizations to prioritize prevention and detection measures. According to recent research, once attackers have valid credentials, only 37% of their actions are blocked. This highlights the need for more effective endpoint detection and response (EDR) solutions and better incident-response procedures.
For those affected by the breach, Veradigm is offering credit-monitoring services where applicable. As the investigation continues, it’s crucial that individuals remain vigilant about protecting their personal data. To minimize the risk of falling victim to similar attacks, we recommend that readers prioritize password security, enable two-factor authentication, and stay informed about emerging cybersecurity threats.
In light of this incident, organizations should reevaluate their third-party vendor management practices and ensure that all partners have robust cybersecurity measures in place. By taking proactive steps to prevent data breaches and responding swiftly when incidents occur, we can reduce the impact of these events on individuals and communities.
Source: Bleeping Computer — 2026-09-09