Veradigm Discloses Data Breach; 3.5M Patient Records May Be Compromised

Veradigm disclosed a data breach after an attacker used compromised credentials from a third-party vendor environment to access a customer-service API and copy patient data. The company, formerly Allscripts Healthcare Solutions, provides EHR, e-prescribing, patient engagement, practice management, and revenue-cycle software to healthcare organizations across the U.S. Veradigm said the copied data did include personal details and Social Security numbers for some patients.

The breach is a textbook example of modern healthcare risk: the attacker did not need to break into Veradigm’s broader network, servers, databases, or core systems. They found a narrower path through a vendor’s compromised credentials and a limited API built for customer services. That distinction matters, but it does not erase the risk. The Gentlemen ransomware group claims it has 3.5 million patient records, including names, home addresses, SSNs, email addresses, phone numbers, and guarantor information, and has threatened to leak the data if Veradigm does not engage. Whether that number proves accurate or inflated, the gap between “limited interface” and “millions of records claimed” is exactly where customers, regulators, and patients demand proof.

The real lesson is that healthcare companies need to treat every API, vendor account, and service workflow as part of the patient-data perimeter. A unified platform like NIKSUN enables organizations to be able to replay the incident like a security camera: vendor credential used, API endpoint accessed, records queried, volume copied, destination contacted, customer accounts affected, and containment completed. That requires one evidence layer across API telemetry, IAM logs, vendor access, customer-service workflows, endpoint activity, DNS, packet data, NetFlow/IPFIX, threat intelligence, and forensic retention — not separate tools arguing after the breach. For Veradigm-style incidents, the value is speed and certainty: prove whether the attacker was truly confined to one interface, validate or disprove the extortion claim, identify every patient and customer impacted, and give legal, security, and executive teams the facts before a ransomware group controls the story. Read more about this story on our LinkedIn page

We use cookies to offer you a better browsing experience and to analyze site traffic. By using our site, you consent to our use of cookies.

Essential Cookies
Site Analytics