Electronic health record company says customer data stolen in breach
Electronic health records company Veradigm told regulators on Tuesday evening that hackers infiltra 2026-9-9 17:18:34 Author: therecord.media(查看原文) 阅读量:7 收藏

Electronic health records company Veradigm told regulators on Tuesday evening that hackers infiltrated a vendor’s systems and stole customer information including Social Security numbers. 

Veradigm provides health record technology and management systems to thousands of hospitals and doctors across the world, reporting $594 million in revenue in 2024. 

The Chicago-based company did not provide specifics about when the data breach occurred but said an unauthorized party “obtained credentials from the vendor’s environment to a [Veradigm] application programming interface used by the vendor to provide services on behalf of the [Veradigm] customers.”

“The unauthorized party used these credentials to download copies of certain personal data of patients, including, in some instances, Social Security numbers; no clinical or medical data was involved,” Veradigm explained in an 8-K filing with the U.S. Securities and Exchange Commission (SEC). 

Veradigm said access was limited to a specific interface, and did not impact the company’s broader environment such as its networks, servers or databases. The incident did not result in operational disruptions, the company added. 

An investigation is still ongoing but the breach has been reported to law enforcement. The company did not respond to requests for comment.

The Gentlemen ransomware gang added Veradigm to its leak site on Friday, claiming to have stolen the health records of 3.5 million patients. The group has launched hundreds of attacks since emerging last fall and recently attacked healthcare companies Nutex and AnMed.  

Formerly known as Allscripts, Veradigm has experienced cybersecurity incidents in the past. It was attacked by the SamSam ransomware gang in 2019 and faced several class action lawsuits due to the incident, which caused outages across thousands of hospitals. 

The company also reported a different cybersecurity incident in December 2025, telling the U.S. Department of Health and Human Services that 2,672,036 people had health data exposed during a breach in December 2024. 

Healthcare targeted

Millions of people have had sensitive information leaked through cyberattacks on healthcare data firms this year. 

Last week, healthcare data migration company Aesto said 9 million people had information leaked during a security incident and Baylor Genetics previously told federal regulators that more than 2.8 million people had medical testing information, laboratory test results and more stolen during a cyber incident in June.

Another 3.7 million people were impacted by a March cybersecurity incident involving electronic health records giant CareCloud and several other firms, including Paylogix announced cyberattacks over the last two weeks that involved patient and customer data. 

In an updated SEC filing on Tuesday, medical device giant Boston Scientific confirmed that its previously announced cyberattack has continued to cause operational issues. 

While the company has been able to evict the hackers and restore some of the affected systems, Boston Scientific said it has had to undergo a “substantial restoration of its distribution network.” They only recently restored a system managing remote monitoring services for cardiac device implants. 

The company admitted that the incident is likely to impact its financial performance and will keep Boston Scientific from achieving its net sales targets for the quarter. 

“The Company anticipates recovering some portion of the impacted revenue as it continues to ramp operations globally, fulfill customer orders and reduce remaining backlogs, however the full impacts are not yet known,” Boston Scientific explained.

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach
如有侵权请联系:admin#unsafe.sh