Published September 12, 2026 — Chicago, Illinois. Veradigm (formerly Allscripts) disclosed a patient data breach after the Gentlemen ransomware gang claimed the attack on their leak site, as reported by BleepingComputer. Veradigm is a major US electronic health record (EHR) and practice-management vendor serving physician practices, small hospitals, and post-acute care providers. The breach potentially exposes protected health information (PHI).
Data last verified September 12, 2026 from BleepingComputer's coverage of the Veradigm breach, Veradigm company information, and HHS Office for Civil Rights HIPAA breach reporting.
Quick Answer
Veradigm (formerly Allscripts) disclosed a patient data breach after the Gentlemen ransomware gang claimed the attack on their leak site. Veradigm is a major US EHR and practice-management vendor serving tens of thousands of physician practices and hospital systems. Specific affected count and breach date are pending Veradigm's full disclosure. Covered entities using Veradigm products must perform HIPAA breach risk assessments and notify HHS if patient data was exposed. Healthcare providers should rotate credentials, audit access logs, and prepare HIPAA breach notifications (BleepingComputer, 2026; HIPAA Privacy Rule).
What we know about the Veradigm breach
| Detail | Information |
|---|---|
| Victim | Veradigm (formerly Allscripts) |
| Threat actor | Gentlemen ransomware gang (claimed on leak site) |
| Reporting source | BleepingComputer |
| Affected data | Potentially PHI - protected health information |
| Affected customer count | Pending full disclosure |
| Reporting status | HIPAA breach notification likely required |
| Customer impact | Tens of thousands of physician practices, small hospitals |
Source: BleepingComputer (2026); Veradigm company information.
About Veradigm
Veradigm is a healthcare technology vendor serving the US market with a comprehensive product portfolio:
| Product | Function | Customers |
|---|---|---|
| Veradigm EHR | Electronic health records for physician practices | Tens of thousands of US practices |
| Veradigm Practice Management | Billing, scheduling, claims management | Thousands of practices |
| Veradigm Hospital Solutions | EHR for small hospitals | Hundreds of small hospitals |
| Veradigm FollowMyHealth | Patient engagement platform | Millions of patients |
| Veradigm Analytics | Population health, quality reporting | Thousands of practices |
| Veradigm Post-Acute | EHR for skilled nursing, home health | Thousands of post-acute providers |
Source: Veradigm company information (2026).
Veradigm (formerly Allscripts) is one of the largest US healthcare IT vendors, serving tens of thousands of physician practices, hundreds of small hospitals, and thousands of post-acute care providers. The combined Allscripts + Eclipsys + Netsmart footprint gives Veradigm deep penetration into ambulatory, inpatient, and post-acute healthcare markets (Veradigm, 2026).
What is the Gentlemen ransomware gang?
The Gentlemen ransomware gang is a Ransomware-as-a-Service (RaaS) operation that emerged in 2025:
- Operating model: RaaS - core team provides infrastructure, affiliates conduct intrusions.
- Targets: Healthcare, manufacturing, financial services, professional services.
- Extortion tactics: Double extortion - encrypt victim data AND threaten to leak on dark-web leak site.
- Leak site: dark-web site lists claimed victims with stolen data samples.
- Negotiation: typically via Tor-based chat with affiliate negotiators.
- Initial access vectors: stolen credentials, phishing, exploitation of internet-exposed services.
The Gentlemen are part of the broader 2025-2026 wave of ransomware-as-a-service operations targeting healthcare. Other active groups in 2025-2026: Akira, BlackCat (ALPHV), Cl0p, LockBit, Play, and INC Ransom. Healthcare is the most-attacked sector for ransomware (Verizon DBIR 2026; BleepingComputer, 2026).
Healthcare vendor breaches: a systemic risk
Veradigm is the latest in a series of major healthcare vendor breaches in 2024-2026:
| Vendor | Incident | Year | Impact |
|---|---|---|---|
| Change Healthcare | Ransomware (ALPHV/BlackCat) | 2024 | ~190M Americans affected; pharmacy claims disrupted nationwide |
| Ascension | Ransomware (Black Basta) | 2024 | 140 hospitals disrupted; ~$1.5B cost |
| Craneware | Data theft (September) | 2026 | Customer hospital data stolen |
| Veradigm | Data breach (September) | 2026 | PHI potentially exposed |
Source: BleepingComputer; Hoodline; Cybersecurity Dive (2024-2026).
Healthcare vendor breaches create cascading risk because a single vendor compromise can expose thousands of downstream healthcare organizations and millions of patients.
HIPAA implications for Veradigm customers
Healthcare organizations using Veradigm products have direct HIPAA breach notification obligations:
- Veradigm as Business Associate: Veradigm handles PHI on behalf of healthcare organizations, making it a HIPAA Business Associate. The Business Associate Agreement (BAA) defines breach notification obligations.
- Customer as Covered Entity: Upon Veradigm's notification, healthcare customers must assess the breach and notify affected patients within 60 days (45 CFR § 164.404).
- HHS OCR notification: if 500+ individuals are affected, customers must notify HHS Secretary within 60 days via the OCR breach portal.
- Media notification: for breaches affecting 500+ individuals in a state, customers must notify prominent media outlets.
- Breach risk assessment: customers must perform a four-factor risk assessment (per 45 CFR § 164.402): nature and sensitivity of PHI; unauthorized person who used PHI; whether PHI was actually acquired/viewed; extent of risk mitigation.
Veradigm will likely coordinate breach notification with affected healthcare customers, providing breach scope, timeline, and remediation guidance. Customers should expect direct contact from Veradigm in the coming weeks (HIPAA Privacy Rule; HHS OCR, 2026).
Immediate actions for Veradigm customers
- Inventory Veradigm integrations - identify all systems that exchange data with Veradigm's platform (EHR, billing, patient portal, lab, imaging).
- Rotate credentials - all admin accounts, integration credentials, API tokens, and service accounts that interact with Veradigm.
- Review access logs for Veradigm-related systems from August 2026 forward. Look for unexpected activity, after-hours access, and unfamiliar IPs.
- Enable enhanced monitoring on all systems that exchange data with Veradigm. Increase SIEM alerting temporarily.
- Coordinate with Veradigm on breach scope, timeline, and remediation. Request Veradigm's incident report when available.
- Review cybersecurity insurance for supply-chain breach coverage. Most policies cover business associate breaches.
- Engage legal counsel for HIPAA breach notification obligations and state law requirements.
- Prepare patient communications - if patient data was exposed, prepare notification templates and credit monitoring offers.
Healthcare vendor risk management best practices
Healthcare organizations should implement comprehensive vendor risk management to mitigate vendor breach exposure:
- Vendor security assessments: require SOC 2 Type II reports, HITRUST certification, and incident history disclosure before contracting.
- Business Associate Agreements: ensure BAAs include 24-48 hour breach notification timelines, forensic cooperation, and credit monitoring obligations.
- Vendor access controls: limit vendor remote access with session recording, time-bound access tokens, and just-in-time access.
- Vendor incident monitoring: subscribe to vendor security advisories; participate in healthcare ISACs (Information Sharing and Analysis Centers).
- Vendor segmentation: isolate vendor systems from critical hospital systems.
- Vendor redundancy: identify backup vendors for critical functions.
- Vendor cyber insurance: require vendors to carry cyber insurance with adequate limits.
FAQ
Will Veradigm pay the Gentlemen ransom?
Veradigm has not publicly disclosed whether they are negotiating with the Gentlemen. Most healthcare organizations face a difficult decision: pay the ransom (often $1M-$10M+) to prevent patient data leak, or refuse and accept the consequences (potential HIPAA fines, litigation, reputational damage). The FBI generally advises against paying ransoms as it incentivizes further attacks, but acknowledges that victims must make their own decisions based on circumstances (FBI, 2024 guidance).
Is the Veradigm breach related to the Allscripts 2018 data breach?
No public connection to the 2018 Allscripts data breach, which affected approximately 1.5 million patients. That breach involved a different threat actor (not ransomware-related) and different attack patterns. Veradigm's current breach is a separate incident (Veradigm, 2018; BleepingComputer, 2026).
How can I tell if my patients' data was exposed in the Veradigm breach?
Wait for Veradigm's official breach notification, which will identify: which Veradigm products were affected, which customers' data was accessed, what types of data were exposed, and the breach timeline. Your organization will then perform a HIPAA breach risk assessment to determine if your patients need to be notified. If you use Veradigm products, prepare breach notification templates and credit monitoring offers in advance (HIPAA Privacy Rule, 45 CFR § 164).
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read more
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.









