2026 Veradigm — vendor API credential theft; patient PII/SSNs (Gentlemen claims ~3.5M)
Data compromised
Company (SEC 8-K): personal data of patients including, in some instances, Social Security numbers; no clinical/medical data. Small number of customers impacted. The Gentlemen claims ~3.5M patient records (names, addresses, SSNs, emails, phones) — unverified census.
Technical writeup
Verified Veradigm Inc. SEC Form 8-K dated September 8, 2026 (reported Sep 9). A third-party vendor cybersecurity incident yielded credentials to a Veradigm API used for customer services; an unauthorized party downloaded copies of certain patient personal data including some SSNs. No clinical/medical data; no operational disruption; access limited to that API (not Veradigm’s broader network). Affected customers/individuals being notified with credit monitoring where applicable. The Gentlemen ransomware group listed Veradigm September 5 claiming ~3.5 million patient records and a September 11 leak deadline — actor census not company-confirmed. Distinct from earlier 2025 Veradigm CA AG stub notices. recordsAffected 0 pending company/regulator census; companyConfirmed true.
Root cause
Unauthorized party obtained vendor credentials to a Veradigm customer-services API and downloaded patient personal data; The Gentlemen listed Veradigm Sep 5 claiming the intrusion