Veradigm just told federal regulators it happened again. On September 8, 2026, the Chicago-based health IT company filed a Form 8-K with the U.S. Securities and Exchange Commission disclosing that stolen vendor credentials had been used to reach into one of its patient-facing APIs and pull down personal data, including Social Security numbers in some records. It is the third distinct security incident tied to Veradigm’s systems to surface in less than two years, and it lands while the company is still mailing out settlement checks from the last one. For a firm that spent decades as a familiar name in doctors’ offices under its old brand, Allscripts, the Veradigm data breach story in 2026 has become less a single event and more a pattern regulators and patients are now tracking closely.
What Veradigm Disclosed on September 8, 2026
According to the 8-K filing and reporting that followed it, the root cause was not a break-in at Veradigm itself. A cybersecurity incident at one of Veradigm’s third-party vendors let an unauthorized party obtain login credentials from inside that vendor’s own environment. Using those credentials, the attacker reached a Veradigm application programming interface that the vendor relies on to deliver services to Veradigm’s healthcare customers, then downloaded copies of patient personal data through that API.
Veradigm has said the compromised credentials were limited to that single vendor-facing interface and did not extend into its broader network, servers, databases, or other internal systems. In the filing itself, the company added a materiality disclaimer that’s become standard language in 8-Ks of this kind: “However, based on the information currently available, the Company does not believe that this incident is reasonably likely to have a material impact on the Company’s business, operations, financial condition, or results of operations.” No count of affected individuals had been published as of this writing. Veradigm has said it has not yet determined the full scope of potential liabilities.
Who Is Veradigm? From Allscripts to a $600 Million Health IT Company
Veradigm’s name still trips people up, and that’s by design of a rebrand rather than an accident. The company operated for years as Allscripts Healthcare Solutions before changing its corporate name to Veradigm Inc. effective January 1, 2023. It kept its NASDAQ ticker, MDRX, through the transition, though the stock has since moved to over-the-counter trading following a delisting process.
The business itself sells electronic health record platforms, practice management software, revenue-cycle and clearinghouse services, and healthcare analytics to providers, payers, and life sciences companies. Recent investor materials put annual revenue in the $580 million to $610 million range, with the company describing itself as serving more than 180,000 physician users across its installed EHR base. That scale is exactly why a Veradigm data breach carries outsized weight: the company sits in the plumbing between doctors, payers, and patient records, which means one compromised vendor relationship can ripple across a large swath of the ambulatory care system.
Inside the Vendor Credential Compromise
The September 2026 incident is a textbook example of what security teams call the third-party risk problem. Veradigm’s own perimeter wasn’t tested at all. Instead, an attacker compromised a vendor that had legitimate, standing access to a Veradigm API, then simply used that vendor’s credentials as if they were the vendor. From Veradigm’s systems’ point of view, the requests looked like normal, authorized traffic from a trusted partner.
That’s a different failure mode from a phishing email landing in an employee’s inbox or a ransomware crew brute-forcing a VPN gateway. It’s closer to what happened in the earlier storage-account incident, where a credential obtained from a Veradigm customer, not an internal Veradigm account, was used to reach a storage account holding patient data. Two incidents, two different outside parties, one common thread: the door that got opened wasn’t Veradigm’s front door. It belonged to somebody Veradigm trusted.
What Data Was Exposed, and What Wasn’t
Veradigm has drawn a specific line around what the September 2026 breach touched. Patient personal data was exposed, and in some records that included Social Security numbers. Clinical or medical information, the company says, was not compromised. That distinction matters for the kind of harm patients should watch for. Exposed SSNs feed identity theft and tax fraud risk. Exposed clinical data feeds a different set of harms, from insurance discrimination to targeted medical scams, and Veradigm maintains none of that left the vendor-facing interface this time.
Compare that to the earlier storage-account breach, which Veradigm has said ultimately affected 2,672,036 individuals once the company finished its review. That incident’s data set was broader, covering health, insurance, payment, and government identifier information tied to a much larger population. The September 2026 event may end up smaller in raw numbers once Veradigm finishes counting, but a breach that includes SSNs pulled straight from a live API carries its own urgency regardless of final headcount.
The Unconfirmed “The Gentlemen” Ransomware Claims
Muddying the picture further, a group calling itself “The Gentlemen” listed Veradigm on a dark-web leak site around September 4 to 5, 2026, claiming to have obtained more than 3.5 million patient records, including names, addresses, Social Security numbers, emails, phone numbers, and guarantor information. Ransomware-tracking sources picked up the listing within days.
Treat that number as an attacker’s claim, not a confirmed fact. Veradigm has not publicly acknowledged this specific incident, no regulator has corroborated it, and no established news outlet has independently verified the 3.5 million figure. Extortion groups routinely inflate victim counts to pressure a target into paying, and leak-site claims have a track record of not matching what companies eventually confirm. Whether “The Gentlemen” listing describes the same intrusion disclosed in the September 8 Form 8-K, an earlier incident, or something else entirely, remains unresolved. What’s confirmed is the SEC filing. What’s alleged is everything else.
Not Veradigm’s First Incident: the 2024 Storage-Account Breach
To understand why September’s disclosure landed with a thud rather than a shock, rewind to the incident Veradigm is still cleaning up. The company has said an attacker accessed a Veradigm storage account around December 2024, using a credential obtained from a Veradigm customer rather than breaking any Veradigm system directly. Veradigm has said it learned of the intrusion on July 1, 2025, seven months after the fact, and began mailing notification letters to affected individuals starting September 22, 2025.
A timeline compiled by breach trackers shows early state filings in Texas and South Carolina put the number affected at roughly 70,000. By the time Veradigm finished its full review, the number had grown by nearly forty times: 2,672,036 individuals, a figure the company confirmed in a June 2026 update and one that ranks the incident among the largest healthcare data breaches reported for 2025. That kind of scope creep, small early estimate followed by a much larger final count, is common in breach investigations and is one reason regulators increasingly push companies toward faster, more conservative initial disclosures.
Veradigm’s Breach Timeline, 2024 to 2026
| Date | Event | Scope | Status |
|---|---|---|---|
| December 2024 (reported as on/around Dec. 15) | Attacker uses a credential from a Veradigm customer to access a Veradigm storage account | Later determined to affect 2,672,036 individuals | Confirmed, notified |
| July 1, 2025 | Veradigm says it first learned of the storage-account intrusion | Scope still under review at this point | Internal discovery |
| September 22, 2025 | Notification letters begin mailing, incident reported to HHS OCR | Initial state filings cited ~70,000 in Texas and South Carolina | Regulatory notification filed |
| Early 2026 | Class action Goodrum, et al. v. Veradigm reaches a proposed $10.5 million settlement | Class of more than 2 million affected individuals | Settlement proposed |
| March 26, 2026 | Court grants final approval of the $10.5 million settlement | Payments of up to $5,000 for documented losses | Final approval |
| June 12, 2026 | Settlement payments begin issuing to approved claimants | – | Payments underway |
| June 2026 | Veradigm confirms final affected count for the storage-account breach | 2,672,036 individuals | Final count confirmed |
| September 4-5, 2026 | “The Gentlemen” lists Veradigm on a dark-web leak site | Claimed 3.5 million+ records, unverified | Unconfirmed claim |
| September 8, 2026 | Veradigm files SEC Form 8-K disclosing a separate vendor/API breach | Patient data including some SSNs, no clinical data, count not yet public | Newly confirmed |
The $10.5 Million Settlement, and Why Payments Started This Summer
The financial fallout from the 2024 breach is no longer theoretical. The case, filed as Goodrum, et al. v. Veradigm, Inc., alleged the company failed to adequately protect patient health, insurance, payment, and government identifier information. Rather than litigate the claims to a verdict, Veradigm agreed to a $10.5 million settlement fund. A court granted final approval on March 26, 2026, and Veradigm began issuing payments to approved claimants on June 12, 2026, with documented-loss claims eligible for up to $5,000 per class member.
That timeline matters for context. Veradigm was still in the middle of paying out a settlement tied to its last confirmed breach when it filed a new 8-K describing another one. For a company whose core product is trust, hospitals and clinics handing over patient records to be managed, that overlap is the kind of detail plaintiffs’ attorneys tend to notice quickly, and shareholders tend to ask about on the next earnings call.
Why Third-Party Vendors Keep Being Healthcare’s Weak Link
Both confirmed Veradigm incidents share a root cause that has nothing to do with Veradigm’s own code or network hardening: someone else’s credentials got stolen first. Healthcare IT is built on a dense web of vendor integrations, EHR platforms, clearinghouses, e-prescribing tools, and analytics feeds, and a health system that hardens its own perimeter can still be exposed through a partner that hasn’t.
This is not unique to Veradigm. Security teams have flagged vendor and supply-chain access as one of the fastest-growing entry points into healthcare data for several years running, precisely because it sidesteps the defenses an organization actually controls. An attacker doesn’t need to find a flaw in Veradigm’s API code if they can simply borrow a legitimate vendor’s key to the front door. Fixing that requires the harder, less glamorous work of credential rotation policies, scoped API access, and continuous monitoring of vendor behavior, not just stronger firewalls.
How Veradigm Stacks Up Against Other 2026 Healthcare Breaches
Veradigm isn’t an outlier this year, it’s part of a trend. Health systems, insurers, and health-adjacent vendors have absorbed a steady drumbeat of breach disclosures and settlements through 2026. Placing Veradigm’s numbers next to a handful of other recent cases shows roughly where it lands on both scale and cost.
| Company | Sector | What Happened | Reported Scale / Cost |
|---|---|---|---|
| Veradigm (formerly Allscripts) | Health IT / EHR vendor | Vendor credential theft used to access a patient API (Sept. 2026), separate storage-account breach (2024) | 2,672,036 individuals (2024 incident), $10.5M settlement, new breach scope undisclosed |
| DaVita | Dialysis / kidney care | Data breach settlement following a cyberattack | $15 million settlement |
| McKesson | Pharmaceutical distribution | ShinyHunters claimed a large-scale data theft | 284 million records claimed by attackers |
| Mathspace | Ed-tech serving school systems | Breach exposed student and staff records | 1.08 million individuals |
| Lemonade | Insurance | Data breach settlement fund established | $10.5 million fund, roughly $10,000 per claim |
| Boston Scientific | Medical device manufacturer | Cyberattack disrupted operations | Cut projected Q3 revenue by up to 7% |
Two things stand out. First, settlement amounts in this range, $10.5 million to $15 million, have become close to a going rate for mid-size healthcare breach litigation, regardless of whether the affected population is in the hundreds of thousands or millions. Second, attacker-claimed numbers (McKesson’s 284 million, “The Gentlemen’s” 3.5 million for Veradigm) tend to run far ahead of what companies ultimately confirm, which is exactly why the confirmed 2,672,036 figure for Veradigm’s 2024 breach still stands as the more reliable data point than the September leak-site claim.
Market and Regulatory Reaction: Reading the Fine Print of the 8-K
Publicly traded companies file Form 8-Ks under SEC rules that require disclosure of cybersecurity incidents determined to be material, or as a voluntary disclosure when a company wants to get ahead of the story. Veradigm’s own language, that it does not currently believe the incident is reasonably likely to have a material impact on its business, is a standard hedge, not a legal conclusion the SEC has blessed. Companies routinely file this disclaimer language and later revise it upward once an investigation runs its course, as Veradigm itself did with the 2024 breach’s affected count.
For a company already trading over the counter after a Nasdaq delisting, a second breach disclosure in under two years adds reputational weight even if the direct financial hit stays contained. Healthcare customers evaluating EHR and revenue-cycle vendors increasingly ask about vendor risk management during procurement, and a repeat disclosure pattern is the kind of detail that shows up in those conversations whether or not it moves the stock price in the short term.
A Record Year for Healthcare Breaches, in Context
Veradigm’s troubles sit inside a much larger pattern. Analyses of the HHS Office for Civil Rights breach portal put 2025 as a record year for large healthcare breaches, with roughly 795 incidents affecting 500 or more individuals reported for the year, touching over 140 million people combined, a scale documented in HIPAA Journal’s 2025 breach report. Through the first several months of 2026, large-breach reports to HHS OCR were already running in the hundreds, with tallies north of 400 incidents and tens of millions of individuals affected by the mid-summer mark.
That backdrop helps explain why a single vendor-credential breach at one EHR company draws the coverage it does. Healthcare data has become one of the most consistently targeted categories of personal information, both because medical records carry more resale value on criminal markets than a stolen credit card number and because the sector’s dependence on third-party vendors keeps creating fresh points of entry faster than security teams can close them.
What Patients and IT Teams Should Do Now
Patients whose providers use Veradigm’s EHR or practice management tools should watch for notification letters, which Veradigm has said will follow once the September 2026 investigation determines who was affected. In the meantime, placing a fraud alert or credit freeze with the major credit bureaus is a reasonable precaution given that Social Security numbers were confirmed among the exposed data types. Anyone who already filed a claim in the $10.5 million settlement from the 2024 breach should hold onto records of that payment separately, since the two incidents are being handled through different processes.
For hospital and clinic IT teams, the practical takeaway is narrower than “improve security.” It’s vendor-specific: audit which third parties hold standing API credentials into systems that touch patient data, confirm those credentials are scoped to the minimum access needed, and set up alerting for unusual download volume through vendor-facing interfaces. Both confirmed Veradigm incidents traveled through exactly that path.
What Happens Next: Five Predictions
- Expect Veradigm to file a follow-up disclosure or amended 8-K within weeks once it determines a specific affected count for the September breach, following the same pattern as the 2024 incident’s scope creep from 70,000 to 2.67 million.
- Plaintiffs’ firms that handled Goodrum v. Veradigm are likely to explore a second class action tied to the September breach, given the SSN exposure and the company’s recent litigation history.
- Watch for HHS OCR to open a formal review given Veradigm’s status as a repeat-reporting entity, a pattern regulators have leaned toward scrutinizing more closely in 2026.
- The “The Gentlemen” leak-site claim will likely either fade without confirmation, a common outcome for unverified extortion listings, or get folded into whatever final scope Veradigm publishes for the September incident.
- Expect healthcare procurement teams to push harder for vendor risk attestations and API access audits in EHR contracts renewed over the next two to three quarters, using Veradigm as the reference case.
Frequently Asked Questions
Is Veradigm the same company as Allscripts?
Yes. Allscripts Healthcare Solutions changed its corporate name to Veradigm Inc. effective January 1, 2023, keeping the same NASDAQ ticker, MDRX, through the rebrand.
How many people were affected by the September 2026 Veradigm breach?
Veradigm had not published a specific affected count as of this writing. The company has said the incident exposed patient personal data, including Social Security numbers in some records, but no clinical or medical information.
Is the “The Gentlemen” ransomware claim against Veradigm confirmed?
No. The group’s claim of 3.5 million-plus stolen records is an unverified attacker-side allegation. Veradigm has not publicly confirmed this specific incident, and no regulator or established news outlet has independently corroborated the figure.
What happened in Veradigm’s earlier 2024 data breach?
An attacker used a credential obtained from a Veradigm customer to access a Veradigm storage account around December 2024. Veradigm has said it learned of the intrusion on July 1, 2025, and began notifying affected individuals on September 22, 2025. The final confirmed count was 2,672,036 individuals.
Can I still file a claim in the Veradigm settlement?
The $10.5 million Goodrum v. Veradigm settlement received final court approval on March 26, 2026, and payments to approved claimants began June 12, 2026. Individuals with questions about eligibility or claim status should consult the official settlement notice they received or the court filings, since claim deadlines for that specific settlement have passed.
Does Veradigm’s breach affect my medical records specifically?
Only if your healthcare provider uses Veradigm’s EHR, practice management, or related services and your data passed through the specific systems involved. Veradigm has said the September 2026 incident did not expose clinical or medical information, though personal identifiers including some Social Security numbers were involved.
Why do so many healthcare breaches trace back to third-party vendors?
Healthcare IT runs on dense vendor integrations, EHR platforms, clearinghouses, e-prescribing systems, and analytics tools that all need some level of API access to patient data. Attackers increasingly target the vendor with weaker security rather than the hospital or health IT company directly, since a stolen vendor credential can grant legitimate-looking access without tripping the target’s own defenses.
