Veradigm warns of patient data breach after ransomware gang claims attack
Veradigm reports patient data breach after ransomware gang claims attack.
Summary
Healthcare technology company Veradigm has disclosed a data breach impacting patient personal data, including Social Security numbers, following a cybersecurity incident at a third-party vendor. The Gentlemen ransomware group has claimed responsibility, alleging to possess 3.5 million patient records and threatening to leak the data if a ransom is not paid. Veradigm is investigating and notifying affected parties, stating that clinical information remains secure.
Full text
Veradigm warns of patient data breach after ransomware gang claims attack By Bill Toulas September 9, 2026 11:31 AM 0 Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. The company says the incident did not cause operational disruptions but affected a small number of customers. Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical practices with electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software. Thousands of hospitals, clinics, and biopharmaceutical firms across the United States use its solutions. The company says in a filing with the U.S. Securities and Exchange Commission (SEC) that an attacker obtained credentials from a vendor’s environment for a Veradigm API reserved for customer services. The threat actor then used their access to copy patient data. Veradigm's disclosure notes that the stolen data includes personal details and Social Security numbers (SSNs) for some of the patients. Clinical or medical information remained safe. “The vendor’s compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company’s environment, including the Company’s broader network, servers, databases, or other systems,” the company says in the SEC filing. After discovering the breach, Veradigm initiated its incident-response procedures, notified law enforcement, and is currently investigating to determine the scope. Affected customers and individuals are being notified, with credit-monitoring services offered where applicable. The investigation is ongoing, but based on current information, Veradigm does not believe the incident is reasonably likely to materially affect its business, operations, financial condition, or results. The Gentlemen ransomware claims the attack Although Veradigm's disclosure did not identify the attacker, The Gentlemen ransomware group has claimed the intrusion on September 5 and listed the company on its data leak site. The threat actor alleges to be holding 3.5 million patient records that include full names, home addresses, SSNs, email addresses, phone numbers, and personally identifiable information or guarantors. The ransomware actor threatens to leak the stolen data by Friday, September 11, if the company doesn't engage in a ransom payment negotiation. The Gentlemen extortion pageSource: BleepingComputer.com The Gentlemen threat actor emerged around mid-2025 and operates as a double-extortion group, combining data theft with data encryption on Windows, Linux, NAS, BSD, and ESXi systems. On its data leak site, the gang listed more than 800 victims from 86 countries and various sectors, including manufacturing, technology, healthcare, transportation, and financial services, indicating opportunistic attacks that rely only on access availability. In April 2026, Check Point reported that it discovered a SystemBC proxy malware botnet with more than 1,500 hosts and linked it to an affiliate of The Gentlemen ransomware gang. In June 2026, ESET said that The Gentlemen was employing a new endpoint detection and response (EDR) killer called GentleKiller. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: Data breach at medical billing firm MCBS affects 1.26 million peopleFrench hospital fined €500,000 after breach exposes data of 727,000Novocure data breach affects more than 1,400 cancer patientsAesto Health says data breach affects over 9.5 million patientsBerlin confirms data theft after Rhysida ransomware attack claims
Indicators of Compromise
- malware — GentleKiller
- malware — SystemBC