Healthcare software company Veradigm says attackers used credentials stolen from a third-party vendor to access a limited customer-services API and copy patient data. The company said the exposed data includes personal information and Social Security numbers for some patients, while clinical information was not affected. The Gentlemen ransomware group claimed the intrusion separately and says it stole 3.5 million patient records, but Veradigm has not confirmed that figure.
Why it matters: Patients and healthcare customers may face identity-theft risk even though medical records were not reportedly exposed. Affected organizations should watch for breach notices, assess exposure through Veradigm integrations and vendor access, and prepare for possible follow-on extortion or phishing.
2026.09.09
99% relevant
This article is a direct update on the same Veradigm incident, adding SEC-filed details that attackers obtained vendor credentials to a Veradigm API, downloaded patient personal data including some Social Security numbers, and that Veradigm says no clinical data or broader internal systems were affected.
Bill Toulas
2026.09.09
100% relevant
This article appears to be the first concrete disclosure tying Veradigm to a third-party credential breach that exposed patient data, with public attribution claims from The Gentlemen but no existing tracked story for this specific incident.
← Back to all stories