Healthcare technology company Veradigm has disclosed a patient data breach after credentials stolen from a third-party vendor were used to access a restricted company interface. The Gentlemen ransomware group has claimed responsibility and alleges it obtained 3.5 million patient records.
Veradigm, formerly known as Allscripts Healthcare Solutions, said the incident affected a small number of customers and did not disrupt its operations. The Chicago-based company provides electronic health records, e-prescribing, patient-engagement and practice-management software to healthcare organisations across the United States.
In a filing with the US Securities and Exchange Commission, Veradigm said an intruder obtained credentials from a vendor’s environment and used them to access an application programming interface intended for customer services. The attacker then copied patient information through that limited connection.
The company said the exposed information included personal details and Social Security numbers for some patients. It said clinical and medical information was not accessed.
“The vendor’s compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company’s environment, including the Company’s broader network, servers, databases, or other systems,” Veradigm said in the filing.
Veradigm has launched an investigation, notified law enforcement and begun contacting affected customers and individuals. Credit-monitoring services will be offered where appropriate, the company said.
The business said it does not currently believe the incident is reasonably likely to have a material effect on its operations, financial position or results. The investigation is continuing as the company works to establish the full scope of the breach.
The Gentlemen claims Veradigm attack
The Gentlemen ransomware group listed Veradigm on its leak site on September 5, although the company has not identified the attackers in its disclosure. The group claims the stolen records contain names, home addresses, Social Security numbers, email addresses, telephone numbers and information about patients or guarantors.
The gang has threatened to publish the data on Friday, September 11, unless Veradigm enters ransom negotiations. The claim has not been independently verified, and it is not clear whether the number of records alleged by the group matches the data identified in Veradigm’s investigation.
The Gentlemen emerged around the middle of 2025 and is described as a double-extortion operation, stealing data while also encrypting systems. Its claimed victims include organisations in healthcare, manufacturing, technology, transport and financial services.
Security researchers have linked the group to a proxy malware botnet and reported that it has deployed tools designed to disable endpoint detection and response software. Those developments underline the risks posed by compromised third-party credentials, but Veradigm has not said that either tool was involved in the incident.
