Veradigm discloses patient data breach after The Gentlemen ransomware gang claims attack
Healthcare technology firm Veradigm disclosed that attackers used credentials stolen from a third-party vendor to reach a customer-service API and copy patient data, after The Gentlemen ransomware gang claimed to hold roughly 3.5 million records.
- Victim
- Veradigm
- records
- 3.5M
On 8 September 2026, Veradigm โ a Chicago-based healthcare technology company formerly known as Allscripts that supplies electronic health record and practice-management software โ disclosed a data breach in a filing with the U.S. Securities and Exchange Commission. The company said an unauthorized party had obtained credentials from a third-party vendor's environment and used them to access a Veradigm API reserved for customer-service functions, then copied patient information.
The disclosure followed the appearance of Veradigm on the leak site of The Gentlemen ransomware operation on 5 September 2026. The group claimed to be holding roughly 3.5 million patient records and threatened to publish the data by 11 September if the company did not enter ransom negotiations. According to the reporting, the exposed information included names, home addresses, Social Security numbers, email addresses and phone numbers, while clinical and medical information was said not to have been taken.
No disruption to core platforms
Veradigm stated that the incident did not disrupt daily operations across its electronic health record and practice-management platforms, and that the intrusion was confined to data accessible through the compromised customer-service API rather than a broad encryption event. Because the theft relied on stolen third-party credentials and involved data exfiltration and extortion rather than system-wide ransomware, the incident is best characterised as a data breach with an ongoing extortion dimension.
The company said it had engaged external cybersecurity specialists, was investigating the scope of the access, and would notify affected individuals as required. With the extortion demand outstanding and the full count of affected patients still being validated, the incident's status remained ongoing at the time of disclosure.
Timeline
The Gentlemen ransomware operation lists Veradigm on its dark web leak site, threatening to publish stolen data if no ransom negotiation begins.
Veradigm discloses the incident in a filing with the U.S. Securities and Exchange Commission, confirming a third party accessed patient data through a customer-service API.
Sources
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/
- hipaajournal.comhttps://www.hipaajournal.com/veradigm-data-breach-2026/
- socradar.iohttps://socradar.io/data-breach/veradigm-thegentlemen-ransomware-2026/