Veradigm Reports Patient Data Breach via Third-Party Vendor Compromise
The healthcare tech provider disclosed a security incident involving stolen credentials, while the 'The Gentlemen' ransomware group claims 3.5 million records were stolen.
Healthcare technology vendor Veradigm disclosed a cyberattack involving a third-party vendor in an SEC filing on September 8, 2026. The breach underscores the persistent vulnerability of the healthcare supply chain to credential-based attacks.
According to the filing, a threat actor used stolen credentials from a third-party vendor to gain access to a limited API interface. Veradigm stated that this access was restricted and did not extend to the company's broader network, servers, or databases. While the company reported that the incident caused no operational disruptions, it noted that the breach impacted data associated with a small number of its customers.
On September 5, 2026, the ransomware-as-a-service group known as "The Gentlemen" claimed responsibility for the attack, listing Veradigm on its leak site. The group claims to have stolen 3.5 million patient records. The Gentlemen has emerged as one of the most dominant ransomware groups of 2026, trailing only Qilin in prevalence. The group has a documented history of targeting the healthcare sector, including a disruptive attack on AnMed in July 2026.
A Pattern of Vulnerability
This incident is the third security event for Veradigm in approximately two years. The company is already managing the fallout from a prior data breach occurring in December 2024, which resulted in a $10.5 million class action settlement in early 2026. The recurrence of these events suggests a systemic struggle to secure patient data against evolving threat actors.
Industry Implications
The breach highlights a critical weakness in the healthcare ecosystem: the reliance on third-party vendors. When a single vendor's credentials are compromised, they can serve as a gateway to sensitive patient personally identifiable information (PII). For patients, the potential exposure of millions of records creates a long-term risk of identity theft. For Veradigm, the incident likely introduces new legal and financial liabilities following its recent multi-million dollar settlement.
What to Watch
Industry observers are now waiting to see if "The Gentlemen" will follow through on threats to leak the stolen data. While Veradigm maintains that the breach was limited to a specific interface, the discrepancy between the company's "small number of customers" description and the ransomware group's claim of 3.5 million records remains a point of concern. Further disclosures regarding the specific types of patient data exfiltrated are expected as the investigation continues.