"The vendor’s compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company’s environment, including the Company’s broader network, servers, databases, or other systems," Veradigm said in a Securities and Exchange Commission filing.
Veradigm's SEC filing and what the company says
Veradigm, the Chicago-based healthcare technology company formerly known as Allscripts Healthcare Solutions, disclosed a data breach in an SEC filing after a cybersecurity incident at one of its third‑party vendors exposed patient personal data. The company stated the event did not cause operational disruptions and affected a small number of customers. Veradigm has initiated incident‑response procedures, notified law enforcement, and is investigating to determine the scope. The filing also says the company “does not believe the incident is reasonably likely to materially affect its business, operations, financial condition, or results” based on current information.
How the intrusion occurred: vendor credentials and a customer‑services API
According to Veradigm, an attacker obtained credentials from a vendor’s environment that provided access to a Veradigm API reserved for customer services. Using that access, the threat actor copied patient data. The company emphasized the intrusion was limited to that interface and did not provide access to Veradigm’s broader network, servers, databases, or other systems. Veradigm said clinical and medical information remained safe.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildData claimed stolen and the scope described by the ransom actor
Veradigm disclosed that stolen information includes personal details and Social Security numbers for some patients. Separately, a ransomware group calling itself The Gentlemen has publicly claimed the intrusion and alleges to be holding 3.5 million patient records containing full names, home addresses, Social Security numbers, email addresses, phone numbers, and personally identifiable information for guarantors. The actor is threatening to publish the data by Friday, September 11, unless Veradigm engages in ransom payment negotiations.
The Gentlemen ransomware group's public claim and tactics
The Gentlemen emerged around mid‑2025 and operates as a double‑extortion group that combines data theft with data encryption across Windows, Linux, NAS, BSD, and ESXi systems, the source material reports. On its data‑leak site the gang listed more than 800 victims from 86 countries across sectors including manufacturing, technology, healthcare, transportation, and financial services, a pattern described as opportunistic attacks that rely on availability of access. In April 2026, Check Point reported a SystemBC proxy botnet of more than 1,500 hosts linked to an affiliate of The Gentlemen, and in June 2026 ESET reported the group employing an endpoint detection and response (EDR) killer called GentleKiller.
Operational impact, notifications, and remediation steps
Veradigm said its operations were not disrupted and that only a small number of customers were affected. The company reported that affected customers and individuals are being notified and that credit‑monitoring services are being offered where applicable. The breach investigation remains ongoing as Veradigm works to determine the full scope of data exposure and continues engagement with law enforcement.
How technologists, affected patients, and adversaries are likely to respond
- Technologists and security teams will be watching credential use and API access closely. The disclosure highlights an access vector tied to vendor credentials and a customer‑services API; the source notes that “Overall prevention scores can hide what happens after initial access” and that “Once attackers are using valid credentials, prevention drops sharply,” a point underscored by a reference to the Blue Report 2026 metrics.
- Affected customers and individuals will be watching notifications and offered protections: Veradigm has said it is notifying affected people and will provide credit‑monitoring where applicable, while the company continues its investigation.
- Adversaries and affiliates may use the announced timeline: The Gentlemen listed Veradigm on its leak site, claimed possession of 3.5 million records, and set a public deadline of September 11 for leaking data if negotiations do not begin—an approach consistent with the group’s double‑extortion behavior documented in the source material.
The record presented by Veradigm and the public claims from The Gentlemen leave a tight set of facts: a vendor credential compromise granted API access, patient personal data (including some Social Security numbers) was copied, Veradigm reports no operational disruption and is offering notifications and credit monitoring, and a criminal group has publicly demanded engagement before a set leak deadline. The investigation and any interaction between Veradigm, law enforcement, and the ransomware actor will determine whether the public claims materialize and whether the company’s assessment of no material business impact holds.




