Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data
The Chicago, Illinois-based practice management and electronic health record company Veradigm (formerly Allscripts Healthcare Solutions) has disclosed a cybersecurity incident in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC).
According to the September 8, 2026, filing, Veradigm recently learned that one of its third-party vendors had experienced a cybersecurity incident that impacted a small number of Veradigm’s customers. Veradigm explained that a threat actor obtained credentials from the vendor’s environment for a Veradigm Application Programming Interface (API) used for customer services. The threat actor was able to use the access to copy patient data.
The threat actor only had access to the API, and no other parts of its network were compromised, including servers, databases, or other systems. Veradigm determined that data stolen in the incident included the personal information of patients, which for certain patients may have involved their Social Security numbers; however, the company has determined that clinical and medical information was not involved and remained secure. As a precaution against data misuse, Veradigm is offering the affected individuals complimentary credit monitoring services.
The investigation is ongoing, and Veradigm has yet to publicly disclose how many individuals have been affected. The company said the incident did not impact its operations, and while the extent of any potential liabilities associated with the incident has not yet been determined, the company does not believe the incident is reasonably likely to have a material impact on the company’s business, operations, financial condition, or results of operations.
Veradigm did not disclose the name of the threat actor behind the attack, which appears to be a prolific threat group called The Gentlemen. The Gentlemen added Veradigm to its dark web data leak site on September 5, 2026. The posting alleges that data exfiltrated in the attack includes names, addresses, phone numbers, email addresses, and other personally identifiable information, and that 3.5 million patient records have been obtained. A threat has been issued to publish the stolen data if the ransom is not paid.



