Veradigm Confirms Patient Data Theft After Vendor Credentials Stolen; Ransomware Crew Claims 3.5 Million Records
The Chicago health-tech firm told the SEC that attackers used a vendor's login to a customer-service API. The Gentlemen ransomware group says it grabbed millions of patient records.

Key points
- Veradigm, formerly Allscripts, told the U.S. Securities and Exchange Commission that attackers stole a vendor's login and used it to copy patient data through a customer-service software connection.
- The stolen data includes names, addresses and Social Security numbers, but not clinical or medical records.
- The Gentlemen ransomware gang listed Veradigm on its leak site on 5 September and claims to hold 3.5 million patient records.
- The gang threatened to publish the data on 11 September if Veradigm refuses to negotiate a ransom.
- Affected patients are being notified and offered credit monitoring; the U.S. Department of Health and Human Services will have jurisdiction under HIPAA breach-notification rules.
Veradigm, the Chicago health-tech company once known as Allscripts, has told U.S. regulators that patient data was stolen after attackers got hold of a login belonging to one of its outside suppliers.
The company sells software to thousands of hospitals, clinics and drug firms across the United States. Its products handle electronic health records, prescriptions, patient billing and appointment systems.
In its filing with the U.S. Securities and Exchange Commission, Veradigm said the intruders obtained credentials from a vendor's environment. Those credentials opened a Veradigm API, a software connection used to move data between systems, that was reserved for customer service work. The attackers then copied patient information through it.
Veradigm says the vendor's login only worked through that one narrow connection. It did not reach the company's wider network, servers or databases.
What was actually stolen?
Names, home addresses, email addresses, phone numbers and Social Security numbers for some patients. Medical and clinical records were not touched, according to Veradigm.
The company has not put a public number on how many people are affected. It described the group of impacted customers as small, though in a company of Veradigm's size that phrase can still cover a lot of individuals.
A ransomware gang calling itself The Gentlemen claims the number is 3.5 million patient records. First reported by BleepingComputer, the group added Veradigm to its dark-web leak site on 5 September and threatened to publish the files on 11 September unless the company opens ransom talks.
Who are The Gentlemen?
A relatively new criminal crew that steals data and encrypts victims' systems, then demands payment to both unlock files and keep the data private. This tactic is known as double extortion.
The group appeared around mid-2025. Its leak site currently lists more than 800 victims across 86 countries, spanning manufacturing, healthcare, transport and finance. That spread suggests the crew hits whoever it can get into rather than picking targets carefully.
Security firm Check Point reported in April 2026 that an affiliate of the group ran a botnet of more than 1,500 machines infected with SystemBC, a piece of malware used to hide criminal traffic. ESET followed in June 2026 with a writeup of GentleKiller, a tool the gang uses to switch off endpoint detection and response software, the security products that watch company laptops and servers for suspicious behaviour.
Timeline and known facts
| Date | Event |
|---|---|
| Around Sept 2025 | Attackers use stolen vendor credentials to access Veradigm customer-service API |
| 5 Sept 2025 | The Gentlemen list Veradigm on their leak site, claiming 3.5 million records |
| 11 Sept 2025 | Deadline set by the gang to publish stolen data |
| Ongoing | Veradigm notifying affected individuals, offering credit monitoring |
Because the stolen data involves patient information held by a U.S. health-tech vendor, the breach falls under the Health Insurance Portability and Accountability Act, known as HIPAA. The U.S. Department of Health and Human Services Office for Civil Rights will handle any regulatory follow-up, and state attorneys general may open their own inquiries.
What should affected patients do?
If you get a notification letter from Veradigm or one of its healthcare clients, take up the free credit monitoring on offer. Place a free fraud alert or credit freeze with the three major U.S. credit bureaus, which stops criminals opening accounts in your name. Be wary of phone calls or emails referencing your medical provider or the breach itself, as scammers routinely follow real breaches with fake support calls asking for more personal details.



