Gentlemen Ransomware Gang Claims 3.5 Million Patient Records from Veradigm Vendor Breach
Veradigm, a Chicago-based company that provides electronic health record systems to thousands of hospitals and doctors worldwide, has disclosed that attackers broke into a third-party vendor's systems and used stolen credentials to access a Veradigm API (application programming interface — a connection point that lets external software communicate with a company's systems), according to The Record.
The attackers used that access to download copies of patient data, including Social Security numbers in some cases. No clinical or medical records were taken. Veradigm says the intrusion was limited to that specific interface and did not reach its broader networks or databases.
The Gentlemen ransomware gang has since claimed responsibility, posting on its leak site that it stole the health records of 3.5 million patients. The group has been active since last autumn and has previously targeted healthcare companies Nutex and AnMed. Veradigm has reported the incident to law enforcement and an investigation is ongoing.
This is not Veradigm's first rodeo. The company, formerly known as Allscripts, was hit by the SamSam ransomware gang in 2019 and reported a separate breach involving over 2.6 million people as recently as December 2025.
What you should do: If you have ever been a patient at a hospital or clinic in the US, it is worth assuming your data may have passed through a health records system at some point. Check whether you are eligible for free credit monitoring through any breach notifications you receive, and consider placing a free credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) to prevent anyone opening accounts in your name.

