Find notable cyber news and cases, enriched with sources, timelines, and signals.

Veradigm patient data leak via vendor API

Data Leak
First reported
Last updated
Happening score
H score 57
1 unique sources, 1 articles

Summary

Hide ▲

Veradigm disclosed a patient data leak that exposed personal details and Social Security numbers for some patients through a third-party vendor access path. The exposure came after an attacker used vendor credentials to reach a limited Veradigm API and copy patient data. Clinical or medical information remained safe, but the leak creates identity-theft risk for affected patients.

Related Happenings

Novocure employee and patient data exposure

Data Leak
H score71 First: 01.09.2026 17:28 Last: 01.09.2026 17:28 Sources 1

About this happening: Novocure exposed employee and patient data in a mid-August cyberattack, affecting more than 1,400 U.S. cancer patients and an undisclosed number of employees. The...

Novocure hit by network compromise

Incident
H score62 First: 01.09.2026 17:28 Last: 01.09.2026 17:28 Sources 1

About this happening: Novocure confirmed a mid-August cyberattack that involved unauthorized access to its systems and exposed patient and employee information. More than 1,400 U.S. cancer pa...

IRhythm patient data exfiltration from third-party business applications

Data Leak
H score34 First: 16.06.2026 09:31 Last: 16.06.2026 09:31 Sources 1

About this happening: iRhythm Holdings disclosed a data breach involving third-party-hosted business applications after a threat actor used social engineering to access data and demande...

Timeline

  1. 09.09.2026 18:31 1 articles · 1h ago

    The Gentlemen claims Veradigm intrusion

    Attribution Update

    The Gentlemen ransomware group claimed an intrusion on Veradigm, listed the company on its data leak site, and said it was holding 3.5 million patient records with full names, home addresses, SSNs, email addresses, phone numbers, and other personally identifiable information or guarantors. The group also threatened to leak the stolen data by Friday, September 11 if ransom negotiations did not begin.

    Show sources
  2. 09.09.2026 18:31 2 articles · 1h ago

    Veradigm discloses patient data breach through vendor API access

    Initial Disclosure

    Veradigm disclosed that a cybersecurity incident at a third-party vendor exposed patients' personal data after an attacker obtained credentials from the vendor's environment for a Veradigm API reserved for customer services and copied data through that limited interface. The disclosed data includes personal details and Social Security numbers (SSNs) for some patients, while clinical or medical information remained safe, the company said the incident did not cause operational disruptions, and affected customers and individuals are being notified with credit-monitoring services offered where applicable.

    Show sources