The Veradigm patient data breach disclosed to the U.S. Securities and Exchange Commission (SEC) has now attracted a ransomware claim, a class action settlement, and a growing list of questions about a company that has been here before. Veradigm, the Chicago-based healthcare technology company formerly known as Allscripts Healthcare Solutions, says an attacker obtained credentials from a third-party vendor’s environment and used them to copy patient data through a limited API reserved for customer services.
The stolen data includes personal details and Social Security numbers (SSNs) for some patients. Clinical or medical information was not affected. Veradigm told the SEC that the compromised credentials provided access only through that narrow interface and did not reach its broader network, servers, databases, or other systems. The company has initiated incident-response procedures, notified law enforcement, and is notifying affected customers and individuals, offering credit-monitoring services where applicable. Based on current information, Veradigm does not believe the incident is reasonably likely to materially affect its business, operations, financial condition, or results.
The Gentlemen Ransomware Group Claims the Attack
Veradigm’s SEC filing did not name the attacker, but The Gentlemen ransomware group claimed the intrusion on 5 September, listing the company on its data leak site. The group alleges it holds 3.5 million patient records, including full names, home addresses, SSNs, email addresses, phone numbers, and personally identifiable information for guarantors. It threatened to publish the data by 11 September if Veradigm did not enter ransom payment negotiations.
The Gentlemen emerged around mid-2025 and operates as a double-extortion group, combining data theft with encryption across Windows, Linux, NAS, BSD, and ESXi systems. Its leak site has listed more than 800 victims from 86 countries across manufacturing, technology, healthcare, transportation, and financial services, a spread that points to opportunistic attacks driven primarily by access availability rather than sector targeting.
According to Healthcare IT News, in 2026 The Gentlemen is the second-most dominant ransomware group, behind only Qilin. In April 2026, Check Point reported a SystemBC proxy malware botnet with more than 1,500 hosts linked to an affiliate of The Gentlemen. In June 2026, ESET said the group was deploying a new endpoint detection and response (EDR) killer called GentleKiller.
Veradigm’s History of Data Incidents
This is not the first time the company has faced a serious breach. According to TEISS, when the company was still known as Allscripts, the SamSam ransomware gang attacked it in 2019, causing outages across thousands of hospitals and triggering several class action lawsuits.
More recently, in December 2025, Veradigm notified the U.S. Department of Health and Human Services that 2,672,036 people had health data exposed during a separate breach in December 2024. That incident is distinct from the current vendor API compromise.
The 2024 breach has already produced legal consequences. According to the Almeida Law Group, Veradigm agreed to pay $10.5 million to settle consolidated class action litigation arising from that incident. Under the terms, class members are eligible for up to $5,000 in documented losses or an estimated $50 alternative cash payment, plus two years of medical data monitoring.
Veradigm’s core business touches thousands of hospitals, clinics, and biopharmaceutical firms across the United States, supplying electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software. The concentration of sensitive patient data across its systems and its vendor relationships makes it a consistent target. The current investigation remains ongoing, with the full scope of affected individuals still to be confirmed.

