Veradigm Confirms Data Breach Following Third-Party Vendor Incident, Ransomware Group Claims Responsibility
Healthcare technology provider **Veradigm** has disclosed a data breach stemming from a cybersecurity incident at one of its third-party vendors. While operational disruptions were avoided, patient data, including Social Security Numbers, was exposed. The **Gentlemen** ransomware group has since claimed responsibility, threatening to leak 3.5 million patient records.
Healthcare technology company **Veradigm**, formerly **Allscripts Healthcare Solutions**, has confirmed a data breach impacting patient data. The incident originated from a cybersecurity compromise at one of its third-party vendors, rather than a direct attack on **Veradigm's** core systems.
According to an **SEC** filing, an attacker obtained credentials for a **Veradigm API** used for customer services from the vendor's environment. This access allowed the threat actor to copy patient data.
**Veradigm** states that the stolen data includes personal details and Social Security Numbers (**SSNs**) for some patients. Crucially, clinical or medical information was not compromised.
"The vendorβs compromised credentials provided access only through that limited interface and did not provide access to any other part of the Companyβs environment, including the Companyβs broader network, servers, databases, or other systems," the company noted in its filing.
Upon discovery, **Veradigm** initiated its incident response protocols, alerted law enforcement, and is actively investigating the full scope of the breach. Affected customers and individuals are being notified, with credit-monitoring services offered where appropriate.
### The Gentlemen Ransomware Claims Attack
Although **Veradigm's** disclosure did not name the perpetrator, the **Gentlemen** ransomware group has publicly claimed responsibility for the intrusion. On September 5, the group listed **Veradigm** on its data leak site, asserting possession of 3.5 million patient records.
The **Gentlemen** group alleges the stolen data includes full names, home addresses, **SSNs**, email addresses, phone numbers, and other personally identifiable information. They have issued a threat to leak this data by Friday, September 11, if ransom negotiations are not initiated.

**The Gentlemen extortion page**
*Source: BleepingComputer.com*
The **Gentlemen** ransomware, which emerged in mid-2025, operates a double-extortion model, combining data theft with encryption across various operating systems, including Windows, Linux, NAS, BSD, and ESXi. The group's data leak site lists over 800 victims from 86 countries, spanning manufacturing, technology, healthcare, transportation, and financial services, suggesting an opportunistic attack strategy.
In April 2026, **Check Point** reported a **SystemBC** proxy malware botnet with over 1,500 hosts, linking it to an affiliate of the **Gentlemen** ransomware gang. Furthermore, **ESET** noted in June 2026 that **The Gentlemen** was deploying a new endpoint detection and response (**EDR**) killer dubbed **GentleKiller**.