Incident
Published 2026-09-09
Verified 2026-09-19

Veradigm: patient PII/SSN copied via vendor API credentials; Gentlemen claim 3.5M records

BleepingComputer (9 September 2026) covers Veradigm's SEC disclosure of a third-party vendor incident: an attacker obtained vendor credentials for a Veradigm customer-services API and copied patient personal details including some Social Security numbers; clinical/medical content and the broader Veradigm network were not accessed per the filing. Veradigm says a small number of customers were affected, notified law enforcement, and is offering credit monitoring where applicable. The Gentlemen ransomware group claimed the intrusion on 5 September and listed Veradigm on its leak site, alleging about 3.5 million patient records and a leak deadline of 11 September 2026 — treat volume and attribution as actor claims pending Veradigm confirmation. Distinct from desk card sharp-office-thegentlemen-20260907 (AU Sharp Office listing). Primary: BleepingComputer (SEC filing).

Exploited in Australia?
unknown

Primary: BleepingComputer — Veradigm / Gentlemen (9 Sep 2026)

breaches identity cloud