top of page

Veradigm Data Breach Exposes Patient Social Security Numbers Through Vendor API

8 minutes ago
2 min read

Healthcare technology provider Veradigm has disclosed a data breach in which attackers used credentials stolen from a third-party vendor to access and copy sensitive patient information.


The Chicago-based company, formerly known as Allscripts Healthcare Solutions, said the incident affected a limited number of customers and did not disrupt its operations. Veradigm supplies electronic health record, e-prescribing, patient engagement, practice management, and revenue cycle software to healthcare organizations across the United States.


According to Veradigm’s filing with the US Securities and Exchange Commission, the compromised credentials belonged to a vendor and provided access to an application programming interface used for customer services.


The exposed information included personal data and, for some patients, Social Security numbers. Veradigm said clinical and medical records were not accessed.


“The vendor’s compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company’s environment, including the Company’s broader network, servers, databases, or other systems,” Veradigm said in its SEC filing.


The company activated its incident response process, contacted law enforcement, and began notifying affected customers and individuals. Credit monitoring is being offered where appropriate. Veradigm said its investigation remains active, but it does not currently expect the incident to materially affect its financial condition or operations.


The Gentlemen Ransomware Group Claims Responsibility


Veradigm did not publicly identify the attacker. However, The Gentlemen ransomware group claimed responsibility and alleged that it stole 3.5 million patient records containing names, addresses, Social Security numbers, email addresses, phone numbers, and guarantor information.


Those claims have not been independently verified.


The Gentlemen operates as a double-extortion group that steals data and may encrypt systems to pressure victims into paying. The operation has claimed hundreds of organizations across healthcare, manufacturing, technology, transportation, and financial services.


John Bruggeman, vCISO at CBTS, said the incident illustrates how narrowly scoped vendor access can still create substantial exposure.


“The damage an attacker can do depends on what that third party’s credentials can reach,” Bruggeman said. “In this case, the compromised 3rd party is reported to have access only to a limited amount of data through a specific API.”


Bruggeman warned that organizations must continuously review vendor credentials, service accounts, API access, machine identities, and emerging AI agents.


“Stolen credentials are particularly difficult to detect because the activity can initially look legitimate,” he said.


The Veradigm breach highlights a growing healthcare cybersecurity problem: attackers may not need to penetrate a company’s central network when a trusted vendor credential already provides a path to valuable patient data.

bottom of page