Veradigm Reports Patient Data Breach Following Third-Party Ransomware Incident
Healthcare technology firm confirms exposure of personal data after ransomware gang claims attack on vendor

Key Takeaways
- Veradigm disclosed a data breach linked to a third-party vendor cybersecurity incident.
- A ransomware gang claimed responsibility for the attack on the vendor.
- Patients' personal data was exposed, though the exact scope remains unspecified.
- The incident underscores the risks of third-party vendor relationships in healthcare technology.
Quick answers
- What happened?
- Veradigm, a healthcare technology company, has disclosed a data breach involving patient personal data. The incident stems from a cybersecurity event at one of the company's third-party vendors, which was claimed by a ransomware group. The exact scope of data exposed and the vendor's identity have not been specified in initial reports.
- What should defenders do?
- Veradigm and affected organizations should conduct a thorough review of third-party vendor security practices, enforce strict data access controls, and monitor for further disclosures regarding the scope of exposed data. Patients should remain vigilant for potential phishing or identity misuse.
Veradigm has confirmed a data breach affecting patients' personal information. The breach was traced to a cybersecurity incident at a third-party vendor. Reports indicate that a ransomware gang, referred to in some media as the 'Gentlemen gang', claimed responsibility for the attack on the vendor. Veradigm stated that the incident exposed patients' personal data, though specific details regarding the volume of records, the nature of the data, and the specific vendor involved have not been fully disclosed. The company is working with the vendor to investigate the incident and mitigate impacts. This incident highlights the ongoing risks associated with third-party supply chains in the healthcare sector.
Security Details
The breach resulted from a cybersecurity incident at a third-party vendor claimed by a ransomware gang. The specific exploitation method, vendor identity, and volume of data exposed have not been confirmed in initial disclosures.
Mitigation
Veradigm and affected organizations should conduct a thorough review of third-party vendor security practices, enforce strict data access controls, and monitor for further disclosures regarding the scope of exposed data. Patients should remain vigilant for potential phishing or identity misuse.
Sources
BleepingComputer
Veradigm warns of patient data breach after ransomware gang claims attack
Sep 9, 2026 · 15:31
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

Misconfigured Supabase Apps Expose Data in Over 16,000 Databases
Security researchers have identified more than 16,000 Supabase-backed applications with publicly accessible databases. The exposure stems from default allow rules that permit unrestricted read access to tables containing personally identifiable information, passwords, and authentication tokens. The findings highlight the risk of misconfigured backend-as-a-service platforms when security defaults are not adjusted for production use.



