Hybrid work arrangement.
Veradigm provides healthcare technology solutions that use real-world data to improve how care is delivered and reimbursed. Its offerings include ePrescribe, clinical data registries, risk adjustment, quality management, and ambulatory claims tools, which draw on real-world data to support better clinical decisions and streamlined operations. The company differentiates itself by offering an integrated platform that serves providers, payers, and biopharma, backed by validated data sources and proven methodologies. Its goal is to improve clinical outcomes and financial efficiency across the healthcare ecosystem.
Company Size
1,001-5,000
Company Stage
IPO
Headquarters
Chicago, Illinois
Founded
N/A
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Hybrid Work Options
Tuition Reimbursement
Veradigm data breach exposes patient Social Security numbers through vendor API. Healthcare technology provider Veradigm has disclosed a data breach in which attackers used credentials stolen from a third-party vendor to access and copy sensitive patient information. The Chicago-based company, formerly known as Allscripts Healthcare Solutions, said the incident affected a limited number of customers and did not disrupt its operations. Veradigm supplies electronic health record, e-prescribing, patient engagement, practice management, and revenue cycle software to healthcare organizations across the United States. According to Veradigm's filing with the US Securities and Exchange Commission, the compromised credentials belonged to a vendor and provided access to an application programming interface used for customer services. The exposed information included personal data and, for some patients, Social Security numbers. Veradigm said clinical and medical records were not accessed. "The vendor's compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company's environment, including the Company's broader network, servers, databases, or other systems," Veradigm said in its SEC filing. The company activated its incident response process, contacted law enforcement, and began notifying affected customers and individuals. Credit monitoring is being offered where appropriate. Veradigm said its investigation remains active, but it does not currently expect the incident to materially affect its financial condition or operations. The Gentlemen ransomware group claims responsibility. Veradigm did not publicly identify the attacker. However, The Gentlemen ransomware group claimed responsibility and alleged that it stole 3.5 million patient records containing names, addresses, Social Security numbers, email addresses, phone numbers, and guarantor information. Those claims have not been independently verified. The Gentlemen operates as a double-extortion group that steals data and may encrypt systems to pressure victims into paying. The operation has claimed hundreds of organizations across healthcare, manufacturing, technology, transportation, and financial services. John Bruggeman, vCISO at CBTS, said the incident illustrates how narrowly scoped vendor access can still create substantial exposure. "The damage an attacker can do depends on what that third party's credentials can reach," Bruggeman said. "In this case, the compromised 3rd party is reported to have access only to a limited amount of data through a specific API." Bruggeman warned that organizations must continuously review vendor credentials, service accounts, API access, machine identities, and emerging AI agents. "Stolen credentials are particularly difficult to detect because the activity can initially look legitimate," he said. The Veradigm breach highlights a growing healthcare cybersecurity problem: attackers may not need to penetrate a company's central network when a trusted vendor credential already provides a path to valuable patient data.
ShinyHunters expose 6.4M in attack on medical supplier McKesson. Have I Been Pwned logs leaked records spanning patients, staff, and providers Published Thu 10 Sept 2026 // 13:13 UTC McKesson's cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time. ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply company in August, although HIBP did not confirm that figure. The cybercriminals told The Register that they issued a $55.2 million extortion demand to prevent the release of McKesson's data - a sum that apparently was not paid, given the subsequent publication of the data. HIBP said: "The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff, and healthcare provider contacts." The types of information exposed vary between individuals, but the records collectively include names, email and physical addresses, genders, dates of birth, phone numbers, employer details, and sensitive health information. This is broadly consistent with ShinyHunters' claims that the stolen data included appointment dates and notes, as well as sensitive medical details such as the locations of patients' cancers. ShinyHunters also claimed to have stolen Social Security numbers (SSNs) as part of the breach, but HIBP did not include these in its analysis of the leaked corpus. The company, which supports 3,300 oncology providers in 29 states, has not publicly confirmed the scale of the breach or issued further details since the last update from its CIO and CTO on August 29. Medical device maker Boston Scientific disclosed a cyberattack at around the same time as McKesson, but has suffered a different kind of fallout. While McKesson is informing the millions of individuals affected by its breach, Boston Scientific told shareholders that disruption from its attack means it expects to miss its sales and earnings guidance for Q3. An update issued on Wednesday said manufacturing, order fulfillment, and shipping operations had been fully restored, although work to restore some business applications continued. Healthtech company Veradigm also disclosed a cyberattack to US regulators this week, days after ransomware group The Gentlemen claimed responsibility. Veradigm said attackers obtained credentials from a third-party vendor's environment and used them to access a company API, stealing patient data without disrupting operations. The Gentlemen claimed to have stolen around 3.5 million records containing personally identifiable information (PII), including SSNs.(R)
Veradigm warns of patient data breach after ransomware gang claims attack. 09/10/2026 Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. The company says the incident did not cause operational disruptions but affected a small number of customers. Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical practices with electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software. Thousands of hospitals, clinics, and biopharmaceutical firms across the United States use its solutions. The company says in a filing with the U.S. Securities and Exchange Commission (SEC) that an attacker obtained credentials from a vendor's environment for a Veradigm API reserved for customer services. The threat actor then used their access to copy patient data.
Veradigm warns of patient data breach after ransomware gang claims attack. * September 9, 2026 * 11:31 AM * 0 Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. The company says the incident did not cause operational disruptions but affected a small number of customers. Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical practices with electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software. Thousands of hospitals, clinics, and biopharmaceutical firms across the United States use its solutions. The company says in a filing with the U.S. Securities and Exchange Commission (SEC) that an attacker obtained credentials from a vendor's environment for a Veradigm API reserved for customer services. The threat actor then used their access to copy patient data. Veradigm's disclosure notes that the stolen data includes personal details and Social Security numbers (SSNs) for some of the patients. Clinical or medical information remained safe. "The vendor's compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company's environment, including the Company's broader network, servers, databases, or other systems," the company says in the SEC filing. After discovering the breach, Veradigm initiated its incident-response procedures, notified law enforcement, and is currently investigating to determine the scope. Affected customers and individuals are being notified, with credit-monitoring services offered where applicable. The investigation is ongoing, but based on current information, Veradigm does not believe the incident is reasonably likely to materially affect its business, operations, financial condition, or results. The Gentlemen ransomware claims the attack. Although Veradigm's disclosure did not identify the attacker, The Gentlemen ransomware group has claimed the intrusion on September 5 and listed the company on its data leak site. The threat actor alleges to be holding 3.5 million patient records that include full names, home addresses, SSNs, email addresses, phone numbers, and personally identifiable information or guarantors. The ransomware actor threatens to leak the stolen data by Friday, September 11, if the company doesn't engage in a ransom payment negotiation. The Gentlemen threat actor emerged around mid-2025 and operates as a double-extortion group, combining data theft with data encryption on Windows, Linux, NAS, BSD, and ESXi systems. On its data leak site, the gang listed more than 800 victims from 86 countries and various sectors, including manufacturing, technology, healthcare, transportation, and financial services, indicating opportunistic attacks that rely only on access availability. In April 2026, Check Point reported that it discovered a SystemBC proxy malware botnet with more than 1,500 hosts and linked it to an affiliate of The Gentlemen ransomware gang. In June 2026, ESET said that The Gentlemen was employing a new endpoint detection and response (EDR) killer called GentleKiller. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Ransomware Group thegentlemen hits: veradigm. HookPhish team Target organization Veradigm veradigm.com Healthcare Summary. In the latest cybersecurity news, Veradigm - an organization based in US - has fallen victim to a ransomware attack conducted by the group thegentlemen. This data breach, discovered on Sep 5, 2026, 18:29 UTC, underscores the increasing need for proactive cybersecurity defenses as HookPhish continue through 2026. Incident report. | Target Organization | Veradigm | | Threat Group | thegentlemen | | Summary | veradigm.com zoominfo.com/c/veradigm-llc/471134180 3.5+ million personal patient records with PII full name, address, social security number, email, address, phone number,guarantors PII ,Score Veradigm Inc. is a publicly traded American healthcare technology and data analytics company (OTC: MDRX), the former Allscripts, founded in 1986 and renamed Veradigm in January 2023, headquartered in Chicago with about 2,300-2,600 employees. Its core asset is one of the largest multi-EHR data networks in US healthcare - over 450,000 connected providers and 200M+ patient records - which it monetizes through three segments: Provider (EHR, practice management, revenue cycle: $473M in 2024), Payer (quality and risk adjustment analytics: $67.3M) and Life Sciences (real-world data and AI-driven evidence: $54M). | | Date of Breach | Sep 4, 2026, 17:26 UTC | | Discovery Date | Sep 5, 2026, 18:29 UTC | | Region | US | | Target Domain | veradigm.com | | Business Sector | Healthcare | How to reduce your ransomware risk. Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure: * monitor the dark web for leaked logins - close the gap attackers exploit. * continuous breach monitoring - close the gap attackers exploit. Disclaimer. HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.