Veradigm patient data leak via vendor API
Data Leak
Summary
Hide ▲
Show ▼
Veradigm disclosed a patient data leak that exposed personal details and Social Security numbers for some patients through a third-party vendor access path. The exposure came after an attacker used vendor credentials to reach a limited Veradigm API and copy patient data. Clinical or medical information remained safe, but the leak creates identity-theft risk for affected patients.
Related Happenings
Novocure employee and patient data exposure
Data Leak
H score71
First: 01.09.2026 17:28
Last: 01.09.2026 17:28
Sources 1
About this happening:
Novocure exposed employee and patient data in a mid-August cyberattack, affecting more than 1,400 U.S. cancer patients and an undisclosed number of employees. The...
Novocure employee and patient data exposure
Data LeakAbout this happening: Novocure exposed employee and patient data in a mid-August cyberattack, affecting more than 1,400 U.S. cancer patients and an undisclosed number of employees. The...
Novocure hit by network compromise
Incident
H score62
First: 01.09.2026 17:28
Last: 01.09.2026 17:28
Sources 1
About this happening:
Novocure confirmed a mid-August cyberattack that involved unauthorized access to its systems and exposed patient and employee information. More than 1,400 U.S. cancer pa...
Novocure hit by network compromise
IncidentAbout this happening: Novocure confirmed a mid-August cyberattack that involved unauthorized access to its systems and exposed patient and employee information. More than 1,400 U.S. cancer pa...
IRhythm patient data exfiltration from third-party business applications
Data Leak
H score34
First: 16.06.2026 09:31
Last: 16.06.2026 09:31
Sources 1
About this happening:
iRhythm Holdings disclosed a data breach involving third-party-hosted business applications after a threat actor used social engineering to access data and demande...
IRhythm patient data exfiltration from third-party business applications
Data LeakAbout this happening: iRhythm Holdings disclosed a data breach involving third-party-hosted business applications after a threat actor used social engineering to access data and demande...
Timeline
-
09.09.2026 18:31 1 articles · 1h ago
The Gentlemen claims Veradigm intrusion
Attribution UpdateThe Gentlemen ransomware group claimed an intrusion on Veradigm, listed the company on its data leak site, and said it was holding 3.5 million patient records with full names, home addresses, SSNs, email addresses, phone numbers, and other personally identifiable information or guarantors. The group also threatened to leak the stolen data by Friday, September 11 if ransom negotiations did not begin.
Show sources
- Veradigm warns of patient data breach after ransomware gang claims attack — www.bleepingcomputer.com — 09.09.2026 18:31
-
09.09.2026 18:31 2 articles · 1h ago
Veradigm discloses patient data breach through vendor API access
Initial DisclosureVeradigm disclosed that a cybersecurity incident at a third-party vendor exposed patients' personal data after an attacker obtained credentials from the vendor's environment for a Veradigm API reserved for customer services and copied data through that limited interface. The disclosed data includes personal details and Social Security numbers (SSNs) for some patients, while clinical or medical information remained safe, the company said the incident did not cause operational disruptions, and affected customers and individuals are being notified with credit-monitoring services offered where applicable.
Show sources
- Veradigm warns of patient data breach after ransomware gang claims attack — www.bleepingcomputer.com — 09.09.2026 18:31
- Veradigm warns of patient data breach after ransomware gang claims attack — www.bleepingcomputer.com — 09.09.2026 18:31