Description

Healthcare technology provider Veradigm disclosed a data breach involving a third-party vendor after attackers obtained vendor credentials that provided access to a limited Veradigm API used for customer services. The threat actor used the compromised credentials to access and copy patient information. The exposed data reportedly includes personal details and Social Security numbers (SSNs) for some individuals, while Veradigm stated that clinical and medical information, as well as its broader network, databases, and other systems, were not affected. Veradigm initiated its incident response process, notified law enforcement, and launched an investigation to determine the full scope of the incident. Affected customers and individuals are being notified, with credit-monitoring services offered where applicable. The company stated that the incident has not caused operational disruption and is not currently expected to materially affect its business or financial condition. The investigation remains ongoing. The Gentlemen ransomware group subsequently claimed responsibility and listed Veradigm on its data leak site, alleging theft of approximately 3.5 million patient records containing names, addresses, SSNs, email addresses, phone numbers, and other personal information. The group threatened to publish the stolen data if ransom demands were not addressed. The incident highlights the risks associated with compromised third-party credentials and API access, particularly within healthcare environments handling sensitive patient information.