Quick Answer
Veradigm (formerly Allscripts) disclosed a patient data breach on September 9, 2026, after The Gentlemen ransomware group claimed 3.5 million patient records. An attacker obtained credentials from a third-party vendor's environment for a Veradigm API used for customer services, then used those credentials to copy patient data — including names and, for some patients, Social Security numbers. Clinical data was not accessed.
Last verified: Sep 16, 2026.
At a glance
- Victim: Veradigm (formerly Allscripts Healthcare Solutions)
- Records claimed: 3.5 million patient records (The Gentlemen); not confirmed by Veradigm
- Vector: Vendor credentials stolen → customer-service API access
- Data exposed: Names, SSNs (some patients), addresses, phones, emails, guarantor PII
- Clinical data: Not accessed (per Veradigm)
- Operational impact: None reported
- HIPAA clock: 60 days from discovery → HHS OCR notification required
What actually happened
The breach pattern is the textbook third-party credential compromise that has become the dominant healthcare-cyber incident of 2026. An attacker obtained credentials from the vendor's environment for a Veradigm application programming interface reserved for customer services. The attacker used those credentials to download copies of certain personal data of patients — including, in some instances, Social Security numbers. No clinical or medical data was involved (Veradigm 8-K filing, September 9, 2026).
Veradigm did not publicly identify the attacker, though The Gentlemen ransomware group claimed responsibility on September 5 by listing Veradigm on its data leak site. The group alleges it is holding 3.5 million patient records that include full names, home addresses, SSNs, email addresses, phone numbers, and personally identifiable information of guarantors. The Gentlemen's threat actor threatens to leak the stolen data by Friday, September 11, 2026, if the company does not engage in ransom payment negotiations (BleepingComputer, September 9, 2026).
The vendor-credential compromise pattern
The 2026 incident pattern across healthcare is the same shape: compromise a third party, harvest valid API credentials, pull data through an interface that was never designed to be exposed. The pattern works because API credentials look legitimate to monitoring systems — they are valid, they are authenticated, and the request looks like normal vendor traffic. The data exfiltration happens slowly enough to evade rate-based detection. By the time the breach is detected, the data is already in the attacker's hands (Tech-Insider, September 10, 2026).
Veradigm specifically said access was limited to a specific interface and did not impact the company's broader environment. That framing is consistent with the pattern: the attacker exploited the trust relationship between the vendor and Veradigm, not a Veradigm vulnerability per se. The vendor has not been publicly named, but the vendor-side breach is the root cause.
Other recent healthcare breaches for context
Veradigm is the third major healthcare breach of September 2026. Aesto Health confirmed 9.5 million records; DaVita confirmed 2.4 million records (with a $15 million settlement) and MCNA Dental confirmed 8.9 million records (with $6.4 million in fees). Separately, Boston Scientific disclosed on September 9, 2026 that its previously announced cyberattack has continued to cause operational issues — the company had to undergo a "substantial" portion of its distribution network reset (The Record, September 9, 2026).
The Gentlemen ransomware gang has also listed Interim HealthCare (a home health and hospice provider operating in roughly 40 U.S. states) and Nutex/AnMed on its leak site. Interim HealthCare of Oklahoma City reported a cybersecurity incident to HHS on July 31, 2026 (HIPAA Journal, September 9, 2026). The pattern: vendor compromise is now the dominant initial-access vector for healthcare ransomware.
What HIPAA requires
Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals, HHS, and — in cases affecting 500 or more people — the media within 60 days of discovery. Given the scale The Gentlemen is claiming, a formal listing on the HHS Office for Civil Rights breach portal would be expected in the coming weeks if the confirmed record count is anywhere close to the gang's figure. Veradigm's disclosure also triggered credit-monitoring obligations where applicable (Veradigm 8-K, September 9, 2026).
For affected patients: enroll in the credit monitoring Veradigm offers, place a fraud alert with the three credit bureaus, and consider a free credit freeze. SSN exposure is the worst category for downstream identity theft because it persists across address changes and is hard to remediate. The Social Security Administration also accepts fraud reports if SSNs are confirmed stolen.
What healthcare organizations should learn
Vendor risk management has overtaken perimeter security as the highest-impact control. Every API credential issued to a vendor is a trust decision that should be reviewed quarterly. Three specific actions for healthcare CISOs this week:
- Inventory all vendor API credentials with access to patient data. The Veradigm breach originated at a vendor; your organization may have similar exposures.
- Apply least-privilege scoping to each vendor API. Veradigm said access was limited to a specific interface — that scoping limited the blast radius. Not every vendor needs access to every patient record.
- Add anomaly detection on vendor API traffic. Credential-stuffing attacks look like normal traffic to rate-based detection; behavioral anomaly detection (volume spikes, off-hours access, new geolocations) catches the pattern earlier.
What to watch next
Two near-term datapoints to track. First, whether HHS OCR posts a Veradigm breach portal entry within the 60-day window — that filing will confirm or deny the 3.5 million record count. Second, whether The Gentlemen publishes the Veradigm dataset on September 11 or later (the September 14 reporting suggests they have not as of the latest update). If published, the dataset will show up on ransomware-tracking services like Ransomware.live within hours.






