Veradigm data breach overview:
- Who: Veradigm Inc. disclosed a cybersecurity incident involving one of its third-party vendors.
- Why: An unauthorized party used credentials stolen from the vendor to download patients’ personal data, including some Social Security numbers.
- Where: Veradigm reported the incident in a filing with the U.S. Securities and Exchange Commission (SEC).
Health records company Veradigm has disclosed that an unauthorized party downloaded patients’ personal data, including Social Security numbers in some instances, following a cybersecurity incident at one of its third-party vendors.
The company reported the Veradigm data breach in a Form 8-K filed with the SEC on Sept. 8.
Veradigm stated it recently learned the vendor’s incident affected certain data associated with a small number of its customers. The unauthorized party obtained credentials from the vendor’s environment for a Veradigm application programming interface, a software connection the vendor used to provide services on behalf of those customers. The party then used those credentials to download copies of patient data.
According to the filing, no clinical or medical data was involved. Veradigm emphasized that the credentials worked only through that limited interface and did not grant access to its broader network, servers, databases or other systems.
“The incident did not result in any operational disruptions,” the company stated.
The company activated its incident response protocols upon learning of the incident and notified law enforcement. It is currently reviewing the compromised data and notifying affected customers and individuals, offering credit monitoring where applicable.
While the investigation is ongoing, Veradigm has not yet determined the extent of any potential liabilities. However, it does not believe the incident is reasonably likely to have a material impact on its business.
Hacking group claims 3.5 million records stolen in Veradigm data breach
Veradigm has not publicly disclosed how many individuals were affected nor has it named the party responsible, according to the HIPAA Journal. The outlet reports that the attacker appears to be a threat group called The Gentlemen, which added Veradigm to its dark web leak site on Sept. 5.
The dark web posting alleges the group obtained 3.5 million patient records containing names, addresses, phone numbers, email addresses and other personal information, the HIPAA Journal reports. The group has threatened to publish the data if a ransom is not paid, although Veradigm’s SEC filing does not address these claims.
The incident is at least the second cybersecurity incident Veradigm has reported to customers within the last year. It follows a 2024 breach the company began notifying patients about in September 2025, which resulted in a $10.5 million class action settlement in January 2026.
At least two lawsuits stemming from this latest incident have already been filed against Veradigm in Illinois federal court.
Have you been notified that your information was involved in this Veradigm data breach? Let us know in the comments.
Don’t Miss Out!
Check out our list of Class Action Lawsuits and Class Action Settlements you may qualify to join!
Read About More Class Action Lawsuits & Class Action Settlements: