Veradigm Discloses Patient Breach After Ransomware Claim
Veradigm disclosed a patient data breach traced to a third-party vendor after the Gentlemen ransomware gang claimed responsibility for the attack.

Veradigm has disclosed a patient data breach. The breach originated at a third-party vendor, not inside Veradigm’s own infrastructure. Patients’ personal data was exposed. The Gentlemen ransomware gang claims responsibility for the underlying attack on the vendor.
Source: BleepingComputer, 2026-09-09.
Confirmed: Veradigm issued a breach disclosure. Third-party vendor involved. Patient personal data exposed.
Unconfirmed: Gentlemen gang attribution. The claim is from the threat actor. Veradigm has not publicly confirmed the specific attacker. Treat accordingly.
What is Veradigm
Veradigm (formerly Allscripts Healthcare Solutions) provides electronic health records, population health software, and data services to physician practices, health systems, and payers across North America. Its customer base means a vendor-side breach maps directly to patient records in clinical settings.
Veradigm is not the first healthcare IT company to see a third-party breach ripple into patient data disclosure this year. Nutex Health’s ransomware incident and McKesson’s ShinyHunters exposure both followed similar patterns: attack on a vendor or service provider, patient data in scope.
What Veradigm has said
Veradigm disclosed the breach as required under HIPAA’s breach notification rules, which mandate notification to affected patients, HHS, and in some cases the media within 60 days of discovering a breach involving 500 or more individuals. The company has not publicly stated how many patients are affected, which vendor was compromised, or what category of personal data is in scope. Those details will be reported once available.
Gentlemen
The Gentlemen gang’s claim is consistent with the group’s observed pattern. This is an extortion-first operation: the group announces attacks on named victims, posts limited proof, and applies pressure during negotiation. Unverified claims from extortion groups should be treated as claims, not confirmed facts, until the victim’s own disclosure aligns with the alleged scope. Veradigm’s disclosure confirms a breach exists. The specific attacker identity and any negotiation status are unconfirmed.
For affected patients
Veradigm is obligated to notify affected patients directly under HIPAA. If you believe you are a Veradigm patient or received care through a practice that uses Veradigm’s EHR systems, watch for a notification letter. The notification should describe what data was involved and what steps are available to you.
Healthcare breach patterns in 2026 have consistently targeted the supply chain: the clinical operator is the named victim, the entry point is a vendor, and the attacker reached patient data through a trusted-vendor relationship. Review vendor access controls and data-sharing agreements. This breach pattern does not resolve itself at the perimeter.
Found this useful? Share it.


