TechNewsReel
Live

Veradigm Patient Data Exposed via Third-Party Vendor Breach

Ransomware group 'The Gentlemen' claims theft of 3.5 million patient records after compromising a vendor API.

TechNewsReel Newsroom · September 11, 2026

Healthcare technology provider Veradigm has disclosed a significant patient data breach stemming from a cybersecurity incident at one of its third-party vendors. The breach underscores the persistent fragility of the healthcare supply chain and the systemic risks associated with external service providers.

In early September 2026, the ransomware group known as 'The Gentlemen' claimed responsibility for the attack, listing Veradigm on its dark-web leak site. The gang asserts it has stolen approximately 3.5 million patient records and has threatened to release the data if its ransom demands are not met. The breach originated when stolen credentials were used to gain unauthorized access to an API at a third-party vendor used by Veradigm.

Security History and Context

Veradigm, formerly known as Allscripts, specializes in electronic health record (EHR) and practice management technology for physician practices and hospitals. This latest incident follows a pattern of security struggles for the company. Veradigm previously suffered a major data breach in 2024, which culminated in a $10.5 million settlement approved in March 2026.

While Veradigm stated that the current incident did not cause operational disruptions and affected only a small number of its customers, the nature of the exposed data remains a concern. The company noted that while clinical and medical information remained safe, personal details and Social Security numbers were exposed for some patients.

Industry Implications

This breach highlights a critical vulnerability in the healthcare sector: the reliance on third-party vendors. When a single vendor is compromised, the resulting ripple effect can expose millions of sensitive patient records across multiple healthcare providers. For a company like Veradigm, which manages the foundational EHR technology used by clinicians, the exposure of Protected Health Information (PHI) creates severe privacy risks for patients and substantial legal liabilities for the firm.

What's Next

Industry analysts are now watching to see if 'The Gentlemen' follows through on its threat to leak the 3.5 million records. While the group's emergence as a ransomware-as-a-service (RaaS) operation since mid-2025 has been noted by threat intelligence firms like Cybereason and Lumu, the full extent of the data exfiltration in this specific case is still being verified. Patients and providers are advised to monitor for signs of identity theft as the situation evolves.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.