Healthcare

Stories 3
Sources 6
Updated 2026.09.09
Veradigm says third-party credential breach exposed patient data after The Gentlemen claimed the attack
Healthcare software company Veradigm says attackers used credentials stolen from a third-party vendor to access a limited customer-services API and copy patient data. The company said the exposed data includes personal information and Social Security numbers for some patients, while clinical information was not affected. The Gentlemen ransomware group claimed the intrusion separately and says it stole 3.5 million patient records, but Veradigm has not confirmed that figure. — Patients and healthcare customers may face identity-theft risk even though medical records were not reportedly exposed. Affected organizations should watch for breach notices, assess exposure through Veradigm integrations and vendor access, and prepare for possible follow-on extortion or phishing.
Sources: Veradigm warns of patient data breach after ransomware gang claims attack, Electronic health record company says customer data stolen in breach
AnMed says cyberattack is still disrupting hospitals and clinics as The Gentlemen ransomware group posts ransom demands on its Facebook page
Nonprofit health system AnMed is still dealing with fallout from a July 26 cyberattack that knocked out IT systems and left multiple facilities closed to appointments. The group calling itself The Gentlemen posted ransom demands on AnMed's Facebook page and claimed to have stolen 6 terabytes of data, including sensitive patient and HR records, though AnMed says it has not yet confirmed the scope of any patient-data impact. The incident was initially described by AnMed as a malware-related cybersecurity disruption affecting four hospitals and clinics in Georgia and South Carolina. — This is a significant healthcare ransomware event because it is disrupting care delivery and may involve highly sensitive medical data. Patients and partners should watch for official breach notices and phishing, while healthcare defenders should review exposure of internet-facing systems, privileged accounts, and social media administration access.
Sources: Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout
iRhythm says social-engineering breach let hackers steal patient health information from third-party business apps
iRhythm disclosed a data breach after hackers stole patient personal and health information from business applications hosted by a third party. The company said the attackers contacted it on June 9, 2026 with a ransom demand and it later confirmed data was exfiltrated; iRhythm says the intrusion involved social engineering and did not affect its cardiac monitoring devices, clinical systems, payment-card data, manufacturing, or distribution operations. — This affects healthcare patients whose protected health information may now be exposed or used in scams and identity abuse. Healthcare organizations and vendors should review third-party app access, harden staff against social-engineering attacks, and watch for follow-on extortion or phishing tied to stolen patient data.
Sources: iRhythm discloses data breach, says hackers stole patient info, Cardiac monitor maker's security skips a beat as data thieves go for the jugular, iRhythm Confirms Data Stolen in Hack