Healthcare technology company Veradigm has disclosed a patient data breach after a cybersecurity incident at one of its third-party vendors exposed personal information belonging to some patients.
Veradigm said the incident did not disrupt its operations but affected a limited number of customers.
Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology provider offering electronic medical records, electronic prescribing, patient engagement, practice management, and revenue cycle management software.
Thousands of hospitals, clinics, healthcare providers, and biopharmaceutical companies across the United States use Veradigm’s platforms and services.
According to a filing with the U.S. Securities and Exchange Commission (SEC), attackers obtained Veradigm API credentials used for customer service from the affected vendor’s environment. The threat actors allegedly used those credentials to access and copy patient data.
Veradigm said the exposed information may include patients’ personal information and Social Security numbers (SSNs). The company stated that clinical and medical information was not affected.
“The vendor’s compromised credentials provided access only through that limited interface and did not provide access to other parts of the company’s environment, including the company’s broader network, servers, databases, or other systems,” the company said in its SEC filing.
After discovering the incident, Veradigm launched its incident response procedures, notified law enforcement, and began an investigation to determine the full scope of the data breach.
Affected customers and individuals will be notified. Where applicable, Veradigm said it will also provide credit monitoring and identity protection services.
While the investigation remains ongoing, Veradigm said that, based on currently available information, it believes the incident is reasonably unlikely to have a material impact on the company’s business, operations, financial condition, or results of operations.
Gentlemen ransomware group claims responsibility
Veradigm did not identify the attackers in its SEC disclosure. However, the Gentlemen ransomware group claimed responsibility for the incident on September 5 and listed Veradigm on its data leak website.
The threat actors claim to have stolen approximately 3.5 million patient records containing names, home addresses, Social Security numbers, email addresses, phone numbers, other personally identifiable information, and guarantor details. These claims have not been independently verified.
The ransomware group threatened to publish the allegedly stolen data by Friday, September 11, unless Veradigm agreed to pay a ransom.

Source: BleepingComputer.com
The Gentlemen threat group emerged around mid-2025 and operates a double-extortion ransomware model. The gang combines data theft with file encryption attacks targeting Windows, Linux, NAS, BSD, and ESXi systems.
On its data leak site, the group claims more than 800 victims across 86 countries and multiple industries, including manufacturing, technology, healthcare, transportation, and financial services. The broad victim list suggests an opportunistic operation focused on exploiting any accessible network or account credentials.
In April 2026, Check Point reported discovering a SystemBC proxy malware botnet containing more than 1,500 hosts and linked the activity to affiliates of the Gentlemen ransomware operation.
In June 2026, ESET reported that the group was using a new endpoint detection and response (EDR) killer known as GentleKiller, designed to disable security tools before ransomware deployment.
The overall prevention score can hide what happens after initial access. When attackers use valid credentials, an organization’s defenses can weaken significantly.
The Blue Report 2026 measures defense techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com



