Back Teiss Veradigm discloses data breach after vendor's systems compromised
Chicago-based healthcare technology company Veradigm told federal regulators Tuesday evening that hackers breached a third-party vendor’s systems and stole personal data, including Social Security numbers, belonging to some of its customers’ patients.
Veradigm, formerly known as Allscripts Healthcare Solutions, supplies electronic health records, e-prescribing, patient-engagement, practice-management and revenue-cycle software to thousands of hospitals, clinics and biopharmaceutical firms across the United States. The company reported $594 million in revenue in 2024.
In an 8-K filing with the U.S. Securities and Exchange Commission, Veradigm said an unauthorized party obtained credentials from the vendor’s environment for an application programming interface used to provide services on behalf of Veradigm customers, then used the access to copy patient data. The filing said clinical or medical data was not involved, and that the compromised credentials provided access only through that limited interface, not the company’s broader network, servers or databases.
Veradigm said the incident did not cause operational disruptions and affected a small number of customers. The company has begun incident-response procedures, notified law enforcement and is investigating to determine the scope of the breach. Affected customers and individuals are being notified, with credit-monitoring services offered where applicable. Veradigm said it does not believe the incident is reasonably likely to materially affect its business, operations, financial condition or results, though the investigation is ongoing. The company did not respond to a request for .
Veradigm’s filing did not name the attacker, but the Gentlemen ransomware group claimed the intrusion and listed the company on its data leak site on September 5, alleging it holds 3.5 million patient records that include full names, addresses, Social Security numbers, email addresses, phone numbers and personally identifiable guarantor information. The group has threatened to leak the data by Friday if Veradigm does not negotiate a ransom payment.
The Gentlemen emerged around mid-2025 as a double-extortion operation that combines data theft with encryption of Windows, Linux, NAS, BSD and ESXi systems, and has listed more than 800 victims across 86 countries in sectors including manufacturing, technology, healthcare, transportation and financial services. The group has also recently attacked healthcare companies Nutex and AnMed. Check Point reported in April that it linked a SystemBC proxy malware botnet of more than 1,500 hosts to a Gentlemen affiliate, and ESET said in June that the group had begun using a new endpoint detection and response killer called GentleKiller.
Veradigm has faced cybersecurity incidents before. The company, then known as Allscripts, was attacked by the SamSam ransomware gang in 2019, an incident that caused outages across thousands of hospitals and led to several class-action lawsuits. In December 2025, Veradigm told the U.S. Department of Health and Human Services that 2,672,036 people had health data exposed during a separate breach in December 2024.
Please take 30 seconds to register
Already have an account? Sign in
"If we think of usability and security as mutually exclusive - we have failed" - Jerrod Chong, Yubico
#teissLondon2018: On the internet, nobody knows you are a fridge
1 in 6 gamers disable all AV in the pursuit of the highest possible speeds
10 malicious Python Libraries discovered on PyPI Repository
126,000 affected by cyberattack on New Zealand patient portal Manage My Health
"If we think of usability and security as mutually exclusive - we have failed" - Jerrod Chong, Yubico
#teissLondon2018: On the internet, nobody knows you are a fridge
1 in 6 gamers disable all AV in the pursuit of the highest possible speeds
10 malicious Python Libraries discovered on PyPI Repository
126,000 affected by cyberattack on New Zealand patient portal Manage My Health
19-year-old claims he hacked into over 25 Tesla cars in 13 countries
2020 cybersecurity trends and resolutions
2025 in review: why cyber-security became a boardroom crisis
Building cyber-resilience across your digital supply chain
Closing the exposure window — unifying continuous threat exposure management
Closing the AI control gap - architecting security across users, applications, and agents
Winston House, 3rd Floor, Units 306-309, 2-4 Dollis park, London, N3 1HF
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
