Healthcare technology company Veradigm has confirmed a new data breach in which an unauthorized party used credentials stolen from a third-party vendor to access a Veradigm application programming interface and download patient information.
Veradigm disclosed the incident in a Sept. 8 filing with the U.S. Securities and Exchange Commission, confirming that the stolen information included personal patient data and, in some cases, Social Security numbers.
The company said no clinical or medical information was involved and that the compromised credentials provided access only through the affected API rather than Veradigm’s broader environment.
Stolen vendor credentials provided access to patient data
According to Veradigm’s Form 8-K filed with the SEC, the incident originated at an unnamed third-party vendor.
Veradigm’s investigation found that an unauthorized party obtained credentials from the vendor’s environment. Those credentials belonged to a Veradigm API that the vendor used while providing services on behalf of Veradigm customers.
The attacker subsequently used the credentials to download copies of patient information.
Veradigm specifically confirmed that the compromised data included:
- Personal information belonging to patients
- Social Security numbers in some cases
The company has not yet disclosed the complete set of exposed data fields, the number of affected patients, the identity of the compromised vendor, or how the vendor’s environment was initially breached.
Veradigm described the incident as affecting data associated with a small number of its customers, although that does not necessarily indicate a small number of individual patients.
Broader Veradigm environment was not accessed
Veradigm said the stolen credentials were restricted to the API and did not provide access to its broader network, servers, databases or other systems.
The company also said the incident caused no operational disruption and emphasized that clinical and medical information was not among the data downloaded by the attacker.
After discovering the incident, Veradigm activated its cybersecurity response procedures and notified law enforcement. Its investigation and review of the affected information remain ongoing.
Affected customers and individuals are being notified, according to the company, with credit monitoring being provided where applicable.
Earlier reports alleged millions of records
Before Veradigm’s disclosure, reports had emerged of a cybercriminal group known as The Gentlemen claiming an attack against the healthcare technology company.
The group reportedly claimed possession of more than 3.5 million patient records containing personal information, including Social Security numbers.
Veradigm’s SEC filing does not attribute the incident to The Gentlemen and does not confirm the claimed 3.5 million-record figure. The overlap between the reported claim and the now-confirmed incident, including the alleged presence of Social Security numbers, is notable, but the attribution and claimed scale remain unverified.
Until Veradigm provides an affected-individual count or additional technical information, the number of patients whose information was downloaded remains unknown.
Veradigm says incident is not materially significant
Veradigm said it has not yet determined the extent of potential liabilities resulting from the breach.
Based on information available as of Sept. 8, however, the company said it does not believe the incident is reasonably likely to materially affect its business, operations, financial condition or financial results.
The latest incident is separate from an earlier Veradigm security incident involving credentials obtained through the network of one of its customers. Veradigm previously disclosed that the earlier compromise allowed an unauthorized party to obtain information from a migration storage account but did not affect its primary network or day-to-day operations.
The Sept. 8 disclosure establishes that patient information was stolen in the latest incident, but several major questions remain unanswered, including the identity of the affected vendor, the number of Veradigm customers involved and the total number of patients whose information was exposed.
Veradigm said its investigation remains ongoing.











