Ransom! Veradigm (SEP-2026)
Veradigm (US) was targeted by the ransomware threat actor thegentlemen, resulting in the exposure of 3.5+ million personal patient records containing highly sensitive PII including full name, address, social security number, email, and phone number, along with guarantors’ PII. Impacted country(s): #UnitedStates

Incident Details

  • Victim: Veradigm
  • Sector: Healthcare
  • Country: US
  • Actor: thegentlemen
  • Source:
  • Discovered: 2026-09-05T18:29:58.376127+00:00
  • Published: 2026-09-04T17:26:38+00:00

Information

  • Veradigm is a publicly traded American healthcare technology and data analytics company, formerly Allscripts, founded in 1986 and renamed in January 2023.
  • Headquartered in Chicago, it employs about 2,300–2,600 people.
  • Its core asset is one of the largest multi-EHR data networks in US healthcare, with more than 450,000 connected providers and over 200 million patient records.
  • The company monetizes this network through three main segments: Provider, Payer, and Life Sciences.
  • The Provider segment covers EHR, practice management, and revenue cycle services, generating $473 million in 2024.
  • The Payer segment focuses on quality and risk adjustment analytics, generating $67.3 million.
  • The Life Sciences segment provides real-world data and AI-driven evidence, generating $54 million.
  • The breach exposed more than 3.5 million personal patient records, including full names, addresses, Social Security numbers, emails, phone numbers, and guarantor information.

Disclaimer: This post is based on public claims made by the ransomware group "thegentlemen". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live