The Veradigm breach: your clinic’s software, a vendor’s stolen key
Veradigm makes the records systems many US practices run on. On 8 September 2026 it confirmed that credentials stolen from one of its vendors were used to pull patient data, Social Security numbers included. It has not said how many people. Here is what is confirmed, what is only claimed, and what to do while the letters are still weeks away.
Veradigm, the health-records company formerly called Allscripts, told the SEC on 8 September 2026 that an attacker used API credentials stolen from one of its vendors to download patient data for a small number of its customers. Names, contact details and in some cases Social Security numbers were involved; Veradigm says medical records were not. The ransomware group The Gentlemen claims 3.5 million records, which nobody has verified. There is no way to check yet. If a practice you use runs Veradigm or Practice Fusion software, freeze your credit, get an IRS Identity Protection PIN, and treat any unexpected breach message as suspect until you have confirmed it with your clinic.
What Veradigm confirmed vs what the attackers claim
The left column comes from Veradigm’s own filing. The right is what the ransomware group posted. The 3.5 million figure belongs in the right column only, and where nobody has said anything, the row says so.
| Question | What Veradigm confirmed | What The Gentlemen claimed |
|---|---|---|
| That something happened | Yes. In a Form 8-K filed with the SEC and dated 8 September 2026, Veradigm said one of its third-party vendors had a cybersecurity incident that exposed patient data belonging to a small number of its customers. | The ransomware group The Gentlemen added Veradigm to its leak site on 5 September 2026, three days before the filing. |
| How the intruder got in | Credentials for a Veradigm API were taken from the vendor’s environment and used to download patient data. Veradigm says that access went only through that limited interface and did not reach its broader network, servers, databases or other systems. The vendor has not been named. | The group has not described its method publicly. |
| How many people | No number. The filing says “a small number” of customers, meaning the clinics and practices that use Veradigm, not a count of patients. | 3.5 million patient records. Nobody outside the group has verified that figure. |
| What was taken | Personal data of patients, including Social Security numbers in some cases. Veradigm says no clinical or medical data was involved. | Full names, home addresses, phone numbers, email addresses, Social Security numbers and personal details of guarantors, the people responsible for paying a patient’s bills. |
| Whether the data is public | Not confirmed. As of 22 September 2026 we have not found credible reporting that the files were released, and no copy has turned up in the breach databases our checker uses. | The group threatened to publish by Friday, 11 September 2026 unless Veradigm negotiated. |
| Letters and credit monitoring | Veradigm says it is notifying affected customers and individuals and offering credit monitoring where applicable. No timetable has been given. | Not applicable. |
| Impact on the company | Veradigm told investors it does not expect the incident to have a material impact on its business. It also said operations were not disrupted. | Not applicable. |
| Lawsuits | Several law firms opened investigations within days of the filing. We have not seen a certified class, and there is no settlement to claim. | Not applicable. |
Sources: Veradigm Inc. Form 8-K, dated 8 September 2026; reporting by BleepingComputer, The Record, HIPAA Journal and Security Magazine, 9–10 September 2026. Status as of 22 September 2026; this page will be updated when Veradigm publishes a count, names affected customers or begins sending letters.
1. What happened, in order
On 5 September 2026 the ransomware group The Gentlemen listed Veradigm on its leak site, claiming 3.5 million patient records and setting a deadline of 11 September to publish them. On 8 September Veradigm filed a Form 8-K with the SEC confirming an incident: credentials for one of its APIs had been stolen from a third-party vendor’s environment and used to download patient data belonging to a small number of its customers, including Social Security numbers in some cases. BleepingComputer, The Record, HIPAA Journal and Security Magazine reported the disclosure on 9 and 10 September. Veradigm has not named the vendor, the customers or a patient count.
2. Why a vendor you have never used has your details
Most medical practices do not build their own records systems. They rent one, and Veradigm, the former Allscripts, is one of the large suppliers: electronic health records, e-prescribing, scheduling and billing for clinics and physician groups. When you fill in a registration form at the front desk, your name, address, phone, insurance details and often your SSN go into that system. This incident went one step further out still: the leak came through a company Veradigm itself works with. That is the same shape as the McKesson and Aesto Health incidents, and it is why the first you hear of it is usually a letter from your clinic weeks later.
3. Why the Social Security number matters more than the rest
Email addresses and phone numbers leak constantly, and most of what they enable is spam. A Social Security number next to a name and home address is different: it is what a lender, a phone carrier or the IRS uses to decide that someone is you. It cannot be reissued except in narrow cases of ongoing misuse, so the exposure lasts for years rather than until the next password change. Veradigm says the SSN was involved only in some instances, and nobody outside the company knows which ones. Until you know, the sensible assumption is that yours could be among them.
4. The honest answer to “am I affected”
Nobody can tell you yet, including us. There is no list of affected practices, the files have not been confirmed as published, and a leak that has not been released cannot be looked up in any breach database. What you can do is narrow it down: ask the practices you have used in the past few years whether they run Veradigm or Practice Fusion software. A yes does not mean your record was taken, since the filing speaks of a small number of customers, but it tells you whether the precautions below are worth your time now.
5. What is worth doing before any letter arrives
Freeze your credit at Equifax, Experian and TransUnion; it is free and it stops new accounts rather than reporting them afterwards. Request an Identity Protection PIN from the IRS, which blocks anyone else from filing a return under your SSN. If you pay for a child’s care, freeze the child’s credit file too, because guarantor details were part of what the attackers described and children’s credit goes unchecked for years. Then read your credit reports at annualcreditreport.com and the explanation-of-benefits statements your insurer sends. If something has already been opened in your name, start at identitytheft.gov.
6. Telling a real notice from a fake one
Real notices will come from Veradigm or from a practice that uses it, by post in most cases, and will offer credit monitoring with an enrolment code. They will not ask you to confirm your SSN, pay a fee or log in through a link. Fakes tend to arrive first, often by email or text, borrowing the company name from the news and asking you to verify who you are. If a message says you were in the Veradigm breach, look up the phone number yourself on the company’s site or call your clinic. Our guide to reading a breach notice walks through what a genuine letter contains.
7. The part that outlasts this incident
Your name, home address, phone number and relatives are already published by people-search and data-broker sites that assembled them from public records, breach or no breach. Those listings are what let someone holding a stolen SSN confirm they have the right person and make an application look plausible. Getting them taken down is the step here that keeps working after the news moves on. For the wider picture on health data, see our medical data breach guide.
You can’t check Veradigm yet. You can check the rest.
Our free scan looks up your email in known breach databases, then checks the part a stolen SSN depends on: the home address, phone number and relatives published about you by 499 broker and people-search sites. PersProtect files the removals and keeps checking.
Check my exposure — free →The Veradigm breach, answered
I have never heard of Veradigm. Why would it have my information?
Because your doctor’s office may run on its software. Veradigm, which was called Allscripts until 2023, sells electronic health records, e-prescribing and practice-management systems to clinics, hospitals and physician groups across the US; the Practice Fusion records system belongs to it as well. Patients almost never deal with the vendor directly. If a practice you used is a customer, your registration details sit in its systems, which is how a company you have never heard of ends up in a breach that involves you.
How can I check whether my records are in it?
There is no way yet, and anything that says otherwise is guessing or fishing. Veradigm has not named the customers involved, the files have not been confirmed as published, and a leak of this kind will only show up in breach-checking databases if it is released and catalogued. The first reliable sign will be a letter from Veradigm or from your clinic. You can ask your practice directly whether it uses Veradigm or Practice Fusion; staff usually know which records system they are on.
Veradigm says no medical data was taken. Is this still serious?
Yes, because of the Social Security numbers. A name, address and SSN together are the working set for opening credit, filing a fake tax return or taking over a benefits account, and unlike a password none of them can be changed. The absence of diagnoses and treatment notes lowers the embarrassment risk and the risk of medical identity theft somewhat. It does nothing for financial identity theft, which is where most of the damage from a leak like this ends up.
What does it mean that guarantor information was mentioned?
A guarantor is whoever is financially responsible for a patient’s bill, most often a parent paying for a child’s care or an adult child handling an elderly parent’s account. If the attackers’ description is accurate, a household can be exposed twice: the patient and the person who pays. Children are a particular concern because nobody checks their credit for years, which is why freezing a child’s credit file is worth doing if your family used an affected practice.
Should I freeze my credit before I get a letter?
If you have been treated anywhere that might use Veradigm software, yes. A freeze at Equifax, Experian and TransUnion is free, takes a few minutes each, and blocks new accounts from being opened in your name whatever an impostor is holding. You lift it yourself when you need credit. Waiting for a notice means waiting weeks, and a freeze is the one step that works whether or not your record turns out to be in the set.
How do I know a Veradigm breach letter is real?
A genuine notice will not ask you to confirm your Social Security number, pay anything, or click through to verify your identity. It will name the incident, list the kinds of data involved and give an enrolment code for credit monitoring with a phone number. Check that number against Veradigm’s own website or your clinic before calling, and type web addresses yourself instead of following a link. Fake breach notices usually show up within weeks of a real disclosure and copy its wording closely.
Can I join a class action?
Firms are collecting names, and signing up with one costs nothing, but there is no certified class and no settlement, and any payout is a long way off. Be wary of emails saying compensation is waiting and asking for bank details or your SSN to release it; that scam follows every large healthcare breach. When a settlement does open, it will appear on our list of open data breach settlements with the official claim site.
A Social Security number can’t be reset
What you can shrink is everything published next to it. See which sites list your address, phone and relatives right now — free, in about a minute.
Run my free exposure scan →