Healthcare tech firm reports data exposure via third-party vendor credentials

Veradigm, a healthcare technology company, disclosed that a third-party vendor's compromised credentials allowed unauthorized access to an API, leading to theft of patient data including Social Security numbers. The company stated that clinical information was not affected and that the incident did not disrupt operations. The Gentlemen ransomware group has claimed responsibility and threatens to leak the data.
The disclosure, filed with the SEC, specifies that the unauthorized access was confined to a customer-service API through stolen vendor credentials. While Social Security numbers and personal details were copied, medical records were not accessed. Veradigm has initiated incident response, notified law enforcement, and is providing credit monitoring to those affected.
The Gentlemen ransomware group, which surfaced in mid-2025, has claimed responsibility. The gang asserts it holds 3.5 million patient records and has set a September 11 deadline for ransom negotiations before leaking the data. Known for double extortion, the group has been linked to a SystemBC botnet and an EDR-killer tool, with over 800 victims listed globally.
The breach could expose affected patients to identity theft and financial fraud, given the theft of Social Security numbers. Individuals may face prolonged risks, such as unauthorized credit applications or tax fraud. Healthcare providers using Veradigm's systems might experience reputational damage and heightened regulatory scrutiny. This incident also underscores the systemic vulnerability of third-party access, suggesting that even narrowly scoped API compromises can erode public trust in digital healthcare infrastructure and data protection practices.