Veradigm Discloses Healthcare Data Breach After ‘The Gentlemen’ Ransomware Gang Claims Attack

Hospital atrium protected by integrated physical security technology

Veradigm (formerly Allscripts) disclosed in an SEC filing that an attacker used stolen third-party vendor credentials to access a limited customer-service API and copy patient data, including names and Social Security numbers, BleepingComputer reported. The company said clinical records were not affected.

The ransomware group calling itself “The Gentlemen” claimed to hold 3.5 million patient records from the breach and threatened to leak the data absent a ransom negotiation.

Why it matters: The breach follows a familiar pattern for healthcare-sector incidents: the initial compromise came through third-party vendor credentials rather than a direct attack on Veradigm’s own systems, underscoring why vendor and supply-chain credential hygiene remains one of the hardest problems in healthcare data security even at companies with mature internal security programs.

Source: BleepingComputer, September 9, 2026, citing Veradigm’s SEC filing.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *