Healthcare technology company Veradigm has disclosed a data breach involving patient information after a cybersecurity incident at one of its third-party vendors. The Chicago-based firm, formerly known as Allscripts Healthcare Solutions, said the attack did not disrupt operations but affected a small number of customers. Veradigm supplies electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software to thousands of hospitals, clinics, and biopharmaceutical firms across the United States.
According to a filing with the U.S. Securities and Exchange Commission, an attacker obtained credentials from the vendor鈥檚 environment for a Veradigm application programming interface reserved for customer services. The threat actor then used that access to copy patient data. The stolen information includes personal details and Social Security numbers for some patients, though clinical or medical information remained safe. The company emphasized that the compromised credentials only provided access through that limited interface and did not reach Veradigm鈥檚 broader network, servers, databases, or other systems.
Veradigm initiated its incident-response procedures after discovering the breach, notified law enforcement, and is currently investigating to determine the full scope. Affected customers and individuals are being notified, with credit-monitoring services offered where applicable. Based on current information, the company does not believe the incident is reasonably likely to materially affect its business, operations, financial condition, or results.
The filing did not identify the attacker, but a ransomware group known as The Gentlemen claimed the intrusion on September 5 and listed Veradigm on its data leak site. The threat actor alleges it is holding 3.5 million patient records that include full names, home addresses, Social Security numbers, email addresses, phone numbers, and personally identifiable information of guarantors. The group threatens to leak the stolen data by Friday, September 11, unless the company engages in ransom payment negotiations.
The Gentlemen emerged around mid-2025 and operates as a double-extortion group, combining data theft with encryption across Windows, Linux, NAS, BSD, and ESXi systems. Its data leak site lists more than 800 victims from 86 countries across sectors such as manufacturing, technology, healthcare, transportation, and financial services, indicating opportunistic attacks based on access availability. In June 2026, cybersecurity firm ESET said The Gentlemen was using a new endpoint detection and response killer called GentleKiller.
The incident highlights a broader weakness in cybersecurity defenses, as prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention effectiveness drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments, underscoring how credential-based intrusions bypass standard safeguards.
More cybersecurity news from TechManNews.






