< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

started · updated

Veradigm reports patient data exposure via third-party vendor breach

Healthcare technology company Veradigm Inc. has disclosed a cybersecurity incident involving a third-party vendor that exposed sensitive patient data. According to regulatory filings with the U.S. Securities and Exchange Commission, an unauthorized party obtained login credentials from within a vendor’s environment. These credentials allowed access to a specific application programming interface (API) used by the vendor to deliver services for Veradigm’s customers.

The breach resulted in the theft of personal data, including Social Security numbers, for a limited group of patients. While the Gentlemen ransomware group has claimed responsibility for the attack, Veradigm stated that no clinical or medical information was compromised. The company also noted that the incident did not cause operational disruptions to its internal networks, servers, or databases, as the intrusion was confined to the vendor-facing interface.

Security experts note that while the breach did not impact system availability, the exposure of Social Security numbers poses long-term risks of identity fraud and phishing for the affected individuals.

Entities

Gentlemen ransomware group · U.S. Securities and Exchange Commission · Veradigm Inc.