Veradigm, a Chicago-based electronic health record vendor serving thousands of hospitals and physician practices, disclosed in a September 8 filing with the Securities and Exchange Commission that an unauthorized party stole patient personal data, including Social Security numbers in some instances, after obtaining credentials belonging to one of its vendors. According to the filing, the stolen credentials granted access to a Veradigm application programming interface that the vendor used to deliver services on Veradigm’s behalf. Veradigm said the access was limited to that single interface and did not reach its broader network, servers or databases, and that no clinical or medical data was involved.
This matters beyond Veradigm’s own customer base because it is the same pattern that has defined healthcare’s worst breaches of the past several months: attackers are increasingly bypassing the EHR vendor’s hardened core systems entirely and instead compromising credentials at a downstream vendor with narrower, API-scoped access. Veradigm’s own filing frames the incident as limited and not likely to be material to its business. That characterization sits uneasily next to a separate claim from the Gentlemen ransomware gang, which added Veradigm to its leak site and says it obtained health records belonging to 3.5 million patients, a figure Veradigm has not confirmed or addressed publicly.
The original insight for security leaders here is the gap itself: a vendor’s own regulatory filing, written for materiality purposes, and an extortion group’s leak-site claim, written to maximize pressure, are describing the same incident in numbers that do not reconcile, and neither has been independently verified. Until Veradigm’s investigation concludes, treat the scope as unresolved rather than settled at either end, and audit which of your own vendors hold API credentials scoped into a partner’s systems the way this one did.
Source: Veradigm Inc., SEC Form 8-K. See also our coverage of Aesto Health’s 9.5 million patient breach and a separate vendor breach that hit a dozen state court systems, both driven by the same third-party access pattern.