Skip to main content
Emerging ThreatsData Breaches

Veradigm Breach Exposes Patient Data After Third-Party Hack

Healthcare office with medical records, computer, and scattered patient papers, hint of security camera.
"The Gentlemen have become one of the busiest ransomware operations in a very short time." — Ross Filipek, CISO at Corsica Technologies.

Veradigm, a healthcare technology organization, is notifying patients after a cybersecurity incident at a third-party vendor exposed patient data. According to Veradigm’s account of the event, a malicious actor stole credentials from a Veradigm API environment that the third party managed, used those credentials to access the environment, and copied patient records. Veradigm says there have been no operational disruptions.

How the intrusion unfolded: stolen credentials, an API environment, and copied records

The breach traces to credentials taken from a third-party-managed API environment tied to Veradigm. With those credentials the attacker gained access to the environment and copied patient data. The source material describes the intrusive step sequence — credential theft, access to the API environment, and exfiltration — but does not report any immediate impact on Veradigm’s operations.

What was taken: Social Security Numbers but no clinical records reported

Veradigm’s notice specifies that the stolen data includes Social Security Numbers. The organization also reports that no clinical or medical information appears to be involved in the files copied by the actor. Despite the absence of clinical data and the lack of operational disruption, Veradigm is warning patients of the incident.

The Gentlemen ransomware group claims responsibility — and what that implies

The Gentlemen ransomware group has claimed responsibility for the attack. Corsica Technologies’ CISO Ross Filipek characterized the group’s behavior and risk profile: “Their playbook makes healthcare especially exposed. They steal sensitive data and spread ransomware quickly across their networks. Their affiliates have shown a willingness to target healthcare without much restraint.” Filipek also warned that “Past Gentlemen activity points toward extortion and public leaks,” and noted that stolen records “can also fuel identity fraud or convincing phishing later.”

Vendor credentials, segmentation, and monitoring: protections Ross Filipek highlights

Responding to the breach, Filipek emphasized three concrete security controls tied directly to how the incident occurred: that vendor credentials require tight controls; that sensitive data should be strongly segmented; and that security teams need monitoring capable of detecting unusual activity early. He concluded bluntly: “With this group, waiting for encryption is already waiting too long.” These recommendations align with the sequence described in the breach — credential theft, API access, and data copying.

What this means for technologists, procurement leaders, and patients

  • Technologists and security teams: Expect to scrutinize third-party API access and credential management. The breach demonstrates how credential compromise in an external environment can allow data copying without causing an immediate operational shutdown.
  • Procurement and vendor managers: Vendor credentials and the security posture of third-party-managed API environments should be central to contracting and oversight. The incident underlines the need for explicit controls and segmentation when external parties manage integration points that carry sensitive identifiers like Social Security Numbers.
  • Patients and the public: Veradigm is warning patients; those affected should be aware that Social Security Numbers were among the items copied and that past activity by the group claiming responsibility points toward extortion, public leaks, and secondary abuses such as identity fraud or convincing phishing.

Verdict in brief: Veradigm avoided an operational shutdown, but the theft of Social Security Numbers and the involvement of a group whose affiliates “have shown a willingness to target healthcare” make this more than a systems incident — it is an incident with downstream privacy and fraud risks. Veradigm’s notice, the mechanics described (credential theft of a third-party-managed API environment), and the claim of responsibility by the Gentlemen ransomware group together frame the next questions clearly: whether stolen records will be used for extortion or public leaks, and how Veradigm and its vendors will tighten credential controls and monitoring to prevent a repeat.

Original story