Veradigm Discloses Patient Data Breach After Ransomware Gang Claims Attack on Third-Party Vendor
Veradigm disclosed a patient data breach after attackers used stolen vendor credentials to access a customer-service API, copying records with Social Security numbers. The Gentlemen ransomware group claims to have stolen 3.5 million records.
Healthcare technology company Veradigm disclosed a patient data breach this week after attackers used stolen credentials for a customer-service API to copy records containing personal details and Social Security numbers Veradigm disclosed a data breach after attackers obtained vendor credentials for a customer-service API, copying patient data including personal details and Social Security numbers. The breach, which Veradigm tied to a ransomware incident at a third-party vendor, follows a claim from the Gentlemen ransomware group that it listed Veradigm on its dark-web leak site in early September 2026 Veradigm disclosed a patient data breach tied to a ransomware incident at a third-party vendor. The Gentlemen ransomware group listed Veradigm on its dark-web leak site in early September 2026.
According to the group, the haul includes roughly 3.5 million patient records lifted from Veradigm’s systems claiming to hold roughly 3.5 million patient records lifted from the company’s systems. Veradigm’s disclosure confirms the core of that claim, though the company has not publicly verified the exact number of records involved.
The mechanics are a now-familiar pattern: a third-party vendor’s compromised credentials provided a path into a primary target’s environment, in this case through an API designed for customer-service functions. Once inside, the attackers were able to exfiltrate data before triggering the ransomware component. What the Gentlemen group claims to have taken — and what Veradigm now confirms was exposed — is the kind of information that turns a system intrusion into a long-term identity-theft problem: names, addresses, dates of birth, and Social Security numbers copying patient data including personal details and Social Security numbers.
For patients, the notification will likely arrive months after the fact. Veradigm’s statement followed the gang’s own publicity, a sequence that has become standard in these incidents — the attackers announce the theft, the victim company investigates, and the public disclosure comes only after the compromise is confirmed. The time lag between exfiltration and notification is baked into the process.
The immediate question for the 3.5 million people whose data is now claimed by the gang is what happens next. Ransomware groups increasingly treat data theft as a separate revenue stream from system encryption, selling or leaking records even if a ransom is paid for decryption keys. Veradigm’s disclosure does not say whether a ransom was demanded or paid, only that patient data was copied. What the company can confirm is that the data was taken, and for the people named in those records, the exposure is already real.