Veradigm, the Chicago health-IT company formerly called Allscripts, filed a Form 8-K on 8 September 2026 confirming that an unauthorised party had obtained credentials from a vendor’s environment to a Veradigm application programming interface the vendor used, and had used them to download personal data of patients associated with a small number of its customers. The data included, in some instances, Social Security numbers. No clinical data was involved, the filing said, and no other part of the company’s environment was accessed.
The Gentlemen extortion operation had listed Veradigm on its leak site on 5 September, claiming about 3.5 million patient records and threatening publication. The filing names no group and gives no count. The vendor is not named either.
A Credential To An Interface
The mechanism is precise and the corpus has filed it before. A vendor holds a credential to a customer’s API because its product needs the data. The vendor is breached, the credential is used from outside, and the customer’s API serves the request as it would any other. The file at 26-0611 recorded the same path into Salesforce environments; 26-0917 records it in a storefront ecosystem the following week. The API did what it was built to do. The control that failed was in the vendor’s environment, and the vendor is the one party nobody has named.
Small Number Of Customers, 3.5 Million Claimed
A health-IT company’s customers are practices and hospitals, and a small number of them can hold millions of patients. The two figures are not in conflict. What the file cannot do is verify the claim, which is the attackers’ and which they made three days before the company confirmed anything. The verification rule at 26-0425 applies: a listing is a claim, and this one arrived first.
The Patient’s Position
The people in the data are patients of a practice that bought software from Veradigm, which shared an interface with a vendor that was breached. Three organisations stand between the patient and the failure, and the notification, where it comes, will come from one of them with a name the patient may not recognise. The corpus filed the same position at 25-0801, and this file adds nothing to it except another instance.
Compiled from Veradigm’s Form 8-K and contemporaneous reporting of the leak-site listing, listed below. The 3.5 million figure is the attackers’ claim; the company has published no count. The vendor was not identified by any source. Graded medium. Corrections: corrections@forensicpost.com.
- Veradigm Inc., Form 8-K, 8 September 2026U.S. Securities and Exchange Commission
- Veradigm discloses patient data breach after Gentlemen gang claims attackBleepingComputer
- Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish DataHIPAA Journal