Veradigm Discloses Data Breach Affecting Patient Social Security Numbers
Electronic health record company Veradigm has reported a data breach where hackers accessed a vendor's interface, stealing patient Social Security numbers and other personal data.

Electronic health records company Veradigm has disclosed a significant data breach that resulted in the theft of patient personal information, including Social Security numbers. The incident occurred when unauthorized actors obtained credentials for a vendor's access to a Veradigm application programming interface (API). This API was used by the vendor to provide services on behalf of Veradigm's customers.
According to an 8-K filing with the U.S. Securities and Exchange Commission (SEC), the attackers used these compromised credentials to download copies of certain personal data belonging to patients. Veradigm emphasized that the breach was limited to this specific interface and did not impact its broader network infrastructure, servers, or databases. Crucially, the company stated that no clinical or medical data was involved in the breach, and no operational disruptions were experienced.
The Gentlemen ransomware gang has claimed responsibility for the attack, adding Veradigm to its leak site and asserting that it stole the records of 3.5 million patients. This group has been active since last fall, launching numerous attacks, with recent targets including healthcare companies Nutex and AnMed. Veradigm, formerly known as Allscripts, has a history of cybersecurity incidents, including a ransomware attack by the SamSam gang in 2019 that caused widespread outages.
This latest incident adds to a growing trend of cyberattacks targeting the healthcare sector. Millions of individuals have had sensitive information compromised through breaches at various healthcare data firms this year. Notably, healthcare data migration company Aesto recently reported a breach affecting 9 million people, while Baylor Genetics disclosed an incident impacting over 2.8 million individuals. Electronic health record giant CareCloud also experienced a breach in March that affected 3.7 million people.
Veradigm stated that an investigation into the breach is ongoing and has been reported to law enforcement. The company has not provided specific details on when the incident occurred or the full scope of the data compromised beyond the mention of Social Security numbers. The limited nature of the access, confined to a vendor-utilized API, suggests a targeted intrusion rather than a widespread network compromise.
In related news, medical device giant Boston Scientific confirmed that a previously announced cyberattack continues to cause operational issues, impacting its distribution network and potentially its financial performance. While the company has made progress in restoring systems, the full extent of the financial impact remains uncertain.
The breach at Veradigm underscores the persistent threats facing the healthcare industry, where sensitive patient data is a prime target for cybercriminals. The reliance on third-party vendors and API integrations, while essential for modern healthcare operations, also introduces potential vulnerabilities that attackers can exploit.
Veradigm's disclosure highlights the critical need for robust security measures not only within healthcare organizations themselves but also within their vendor ecosystems. The company's assurance that clinical data was not compromised offers some relief, but the exposure of Social Security numbers remains a serious concern for affected patients.
The breach at Veradigm, which involved a third-party vendor's compromised login credentials being used to access a Veradigm API, exposed patient data including Social Security numbers. While no clinical information was compromised, the incident highlights the ongoing risks associated with third-party vendor access in the healthcare sector. Veradigm is currently notifying affected customers and offering credit monitoring services.