Veradigm data breach (2026): what was exposed and what to do

Updated Corrections

September 16, 2026

We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.

What happened

Veradigm (formerly Allscripts), a Chicago-based electronic health record and practice-management technology company, disclosed a breach in a Form 8-K filed with the SEC on September 8, 2026. The company said an unauthorized party obtained credentials from one of its third-party vendors' environments to a Veradigm application programming interface (API) that the vendor used to provide services to Veradigm customers. The attacker used that access to download copies of certain patient personal data.

Veradigm said the stolen data included personal data of patients and, in some instances, Social Security numbers, and that no clinical or medical data was involved. It said the access was limited to that interface and did not reach its broader network, servers, or databases, that a small number of its customers were affected, and that operations were not disrupted. Veradigm notified law enforcement and said affected customers and individuals are being notified, with credit monitoring offered where applicable.

Around September 5, 2026, the Gentlemen ransomware group claimed the attack and alleged it took about 3.5 million patient records, including names, home addresses, Social Security numbers, emails, and phone numbers. Veradigm has not confirmed that figure or a total count of affected people.

This is separate from an earlier Veradigm breach, discovered in July 2025, that the company later said affected about 2.67 million people.

Sources

What data was exposed

The following types of personal data were compromised:

  • Patient personal data (Veradigm has not published a full field list)
  • Social Security numbers (in some instances, per Veradigm)
  • Names, home addresses, email addresses, and phone numbers (claimed by the attackers, not confirmed by Veradigm)

Breach details

Detail Value
Breach name Veradigm
Date September 2026
Disclosed September 8, 2026 (SEC Form 8-K)
Accounts affected Not disclosed (attackers claim about 3.5 million records)
Domain veradigm.com

This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your personal data is involved, contact our support team.

We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Veradigm; it reflects a publicly reported security incident.

For whether your personal data was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you), not this page alone.

What to do now

Based on the data exposed in this breach, here are the steps you should take:

  • Watch your mail for a notice from Veradigm or your healthcare provider, and enroll in any credit monitoring it offers using the instructions in that letter.
  • If you get a notice or your provider uses Veradigm, place a free credit freeze with Equifax, Experian, and TransUnion. Some patients' Social Security numbers were involved.
  • Treat messages that claim to be from your clinic, hospital, or Veradigm and ask you to confirm your Social Security number or personal details as phishing, unless you started the contact through a number you already trust.
  • Review your credit reports and bank statements for new accounts or hard inquiries you did not authorize.
  • Ask your provider's office whether it was among the affected Veradigm customers.

What to do after a breach

A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.

More breaches

Free personal data exposure scan

We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.