Veradigm warns of patient data breach after ransomware gang claims attack

2 hours ago 6

Veradigm warns of patient data breach after ransomware gang claims attack

Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data.

The company says the incident did not cause operational disruptions but affected a small number of customers.

Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical practices with electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software.

Thousands of hospitals, clinics, and biopharmaceutical firms across the United States use its solutions.

The company says in a filing with the U.S. Securities and Exchange Commission (SEC) that an attacker obtained credentials from a vendor’s environment for a Veradigm API reserved for customer services. The threat actor then used their access to copy patient data.

Veradigm's disclosure notes that the stolen data includes personal details and Social Security numbers (SSNs) for some of the patients. Clinical or medical information remained safe.

“The vendor’s compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company’s environment, including the Company’s broader network, servers, databases, or other systems,” the company says in the SEC filing.

After discovering the breach, Veradigm initiated its incident-response procedures, notified law enforcement, and is currently investigating to determine the scope.

Affected customers and individuals are being notified, with credit-monitoring services offered where applicable.

The investigation is ongoing, but based on current information, Veradigm does not believe the incident is reasonably likely to materially affect its business, operations, financial condition, or results.

The Gentlemen ransomware claims the attack

Although Veradigm's disclosure did not identify the attacker, The Gentlemen ransomware group has claimed the intrusion on September 5 and listed the company on its data leak site.

The threat actor alleges to be holding 3.5 million patient records that include full names, home addresses, SSNs, email addresses, phone numbers, and personally identifiable information or guarantors.

The ransomware actor threatens to leak the stolen data by Friday, September 11, if the company doesn't engage in a ransom payment negotiation.

The GentlemenThe Gentlemen extortion page
Source: BleepingComputer.com

The Gentlemen threat actor emerged around mid-2025 and operates as a double-extortion group, combining data theft with data encryption on Windows, Linux, NAS, BSD, and ESXi systems.

On its data leak site, the gang listed more than 800 victims from 86 countries and various sectors, including manufacturing, technology, healthcare, transportation, and financial services, indicating opportunistic attacks that rely only on access availability.

In April 2026, Check Point reported that it discovered a SystemBC proxy malware botnet with more than 1,500 hosts and linked it to an affiliate of The Gentlemen ransomware gang.

In June 2026, ESET said that The Gentlemen was employing a new endpoint detection and response (EDR) killer called GentleKiller.

article image

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Read Entire Article