Veradigm Inc., a nationwide electronic health records and practice-management vendor formerly known as Allscripts, disclosed on September 8, 2026 that a hacker used stolen vendor credentials to pull patient data from its systems. A ransomware group calling itself The Gentlemen claims it holds more than 3.5 million patient records and says it will publish them if Veradigm doesn’t pay by September 11, 2026 — two days from now.
Veradigm Inc. (Nasdaq: MDRX), a Chicago-based company whose electronic health record and practice-management software is used by thousands of hospitals, clinics, and biopharmaceutical companies across the country, filed a report with the Securities and Exchange Commission on September 8, 2026 disclosing a data security incident. According to Veradigm’s own filing, an unauthorized party used credentials obtained from a compromised third-party vendor to access a Veradigm application programming interface (API) and download personal data belonging to patients, including, in some instances, Social Security numbers. Veradigm states that no clinical or medical data was involved and that the API did not give the intruder access to its broader network.
Source: Veradigm Inc. SEC Form 8-K, Item 8.01, filed 09/08/2026 (sec.gov/Archives/edgar/data/1124804/000119312526385249/mdrx-20260908.htm).
A Hacking Group Claims a Much Bigger Breach — and a Two-Day Deadline
Three days before Veradigm’s SEC filing, a ransomware and extortion group calling itself The Gentlemen posted a listing on its dark web leak site claiming to have obtained more than 3,500,000 patient records, including names, contact information, and Social Security numbers. According to reporting from BleepingComputer, the group’s claim goes further than Veradigm’s own filing — it says the stolen data also includes personal information belonging to guarantors, the financially responsible parties on a patient’s account, such as a parent or spouse, who may have no direct relationship with Veradigm at all. The group has reportedly set a deadline of Friday, September 11, 2026 to publish the data if Veradigm does not enter ransom negotiations.
Veradigm has not confirmed the number of records involved or the guarantor-data claim. This is an unverified statement from a criminal extortion group, not a confirmed fact, and Emery | Reddy is presenting it as such. But the gap between Veradigm’s own description — ‘a small number of the Company’s customers’ — and the scale of the attacker’s claim is itself worth noting: Veradigm’s customers are healthcare provider organizations, not individual patients, so a small number of affected customers is fully consistent with a very large number of affected patients underneath them.
Source: BleepingComputer, ‘Veradigm discloses patient data breach after Gentlemen gang claims attack,’ 09/08/2026; Ransomware.live leak-site listing dated 09/05/2026. The Gentlemen is a double-extortion ransomware operation active since mid-2025, linked by Check Point to a large proxy botnet and documented by ESET as using custom EDR-killing tools; it lists more than 800 victims across 86 countries.
This Is Veradigm’s Third Data Security Incident in Under Two Years
This is not Veradigm’s first reported breach. State regulator filings show the company — operating at the time as Veradigm LLC — previously reported a separate intrusion that began in mid-December 2024, which affected 845 Washington residents according to Washington’s own breach database, and which the company did not report to Washington regulators until December 2025 — roughly five months after becoming aware of it. That earlier incident, which affected more than 2 million patients nationwide, was also reported to California and Texas regulators (43,684 Texas residents) in the second half of 2025, and led to a separate class action settlement of $10.5 million that received final court approval in March 2026. A third, distinct set of Veradigm lawsuits was filed in the second half of 2025 over a separate incident from around July 2025. Read together with this new September 2026 incident, that is three reported Veradigm data security events in roughly twenty-one months.
Source: Washington State Office of the Attorney General breach notification database (Veradigm LLC, 845 WA residents, intrusion 12/15-12/16/2024, submitted 12/02/2025); Texas Attorney General data breach notifications (43,684 TX residents, published 12/19/2025); HIPAA Journal reporting on the $10.5 million class action settlement (final approval 03/26/2026). This settlement and the prior incident are separate from, and already resolved independently of, the new September 2026 incident described above.
Two Lawsuits Already Filed
Litigation over this new incident moved fast. Clay v. Veradigm, Inc. was filed in the U.S. District Court for the Northern District of Illinois (No. 1:26-cv-10827) the same day as Veradigm’s SEC disclosure, September 8, 2026. A second case, Walker v. Veradigm, Inc. (No. 1:26-cv-10852), was filed in the same court on September 9, 2026. Both cases are a matter of public court record.
What to Do If You’re a Veradigm Patient
- Watch for a notice letter from Veradigm or from the healthcare provider that uses its systems
- Monitor your credit reports and financial accounts for unfamiliar activity
- Be alert for phishing emails or calls referencing your medical provider
- If you are a guarantor on someone else’s medical account — a parent or spouse, for example — watch your own accounts too, given the attacker’s claim that guarantor data was included
Do You Have Legal Options?
Companies that collect and store sensitive patient and financial data have a legal duty to secure it and to notify affected individuals without unreasonable delay. A repeat history of security incidents, like the one reflected in Veradigm’s regulatory filings, is often central to that kind of claim.
If you’ve received a notice about this breach, or you’re a patient of a provider that uses Veradigm’s software, contact Emery | Reddy today for a Free Case Review.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.
FAQ
What happened in the Veradigm data breach?
Veradigm disclosed on September 8, 2026 that a hacker used stolen credentials from a third-party vendor to access an API and download patient data, including Social Security numbers in some cases. A ransomware group separately claims to hold more than 3.5 million patient records and has threatened to publish them.
How many people are affected?
Veradigm has not disclosed a number. The attacker group The Gentlemen claims over 3.5 million records, but that is an unverified claim from a criminal group, not a confirmed figure from Veradigm.
Was my medical information exposed?
Veradigm’s own filing states that no clinical or medical data was involved. The attacker’s broader claim includes names, contact information, Social Security numbers, and possibly guarantor information, but has not been independently verified.
What is a ‘guarantor’ and why does it matter here?
A guarantor is the person financially responsible for a patient’s account, often a parent or spouse. According to reporting on the attacker’s claims, guarantor data may have been included in the stolen files — meaning people who were never Veradigm patients themselves could still be affected.
Has this happened to Veradigm before?
Yes. This is the third Veradigm data security incident reported in roughly the last two years, including a 2024-2025 incident that led to a $10.5 million class action settlement approved in March 2026. That settlement covers the earlier incident, not this new one.
Do I have a legal claim?
Companies that collect and store sensitive patient and financial information have a legal duty to secure it and to notify affected individuals without unreasonable delay. If you’ve received a notice letter, or you’re a patient of a provider that uses Veradigm’s software, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.