Skip to content
TrustList
News

Veradigm discloses patient data theft via stolen vendor credentials

Editorial

By TrustList Editorial

Veradigm disclosed on 8 September 2026 that stolen vendor credentials were used against one of its APIs to copy patient data, including Social Security numbers for some; a ransomware group’s 3.5-million-record claim is unconfirmed by Veradigm.

About Veradigm discloses patient data theft via stolen vendor credentials

Veradigm discloses patient data theft via stolen vendor credentials

8 September 2026 — Veradigm Inc. (the electronic health records and practice-management vendor formerly known as Allscripts) disclosed in an SEC filing on 8 September 2026 that an unauthorized party obtained credentials from one of its vendors and used them against a Veradigm-hosted API the vendor was authorized to use on customers' behalf, downloading copies of patients' personal data. Veradigm's own filing says the data included, for some patients, Social Security numbers, but no clinical or medical records, and that the compromised credentials gave access only through that one limited interface, not the company's broader network.

What Veradigm confirms, and what is only a claim

  • Veradigm's own filing says the incident did not cause operational disruptions, affected a limited set of customers, and that law enforcement has been notified.
  • The ransomware group calling itself "the Gentlemen" claimed the intrusion on 5 September and listed Veradigm on its leak site, alleging it holds 3.5 million patient records with names, home addresses, Social Security numbers, emails and phone numbers.
  • Veradigm's own disclosure does not confirm the 3.5-million figure or that exact description of the data — that account is the threat actor's alone, and whether any data has actually been published was not independently confirmed as of 25 September 2026.

If you use Veradigm or a connected vendor

  • If your organisation reaches Veradigm's platform through a third-party vendor or integration, ask that vendor directly whether its own credentials were among those compromised — the attack path ran through vendor access, not a direct breach of Veradigm's systems.
  • Ask Veradigm which of your patients, if any, are on its affected list rather than assuming a "limited number of customers" excludes you.
  • Because Social Security numbers were exposed for at least some patients, affected individuals should take up the credit monitoring Veradigm is offering, and organisations should watch for phishing that references this incident by name.

Sources