Threat trackers recorded a September 4 leak-site posting in which The Gentlemen said it took more than 3.5 million patient records from Veradigm, a US vendor of electronic health record and practice workflow software. The entry lists addresses, Social Security numbers, phone numbers, emails, and guarantor information among the captured material, and Veradigm has not confirmed the intrusion.
One second after the Veradigm entry appeared, The Gentlemen added Zdrowit, a Polish pharmacy chain, to the same leak page and published a sample of what it says was stolen. Neither company has acknowledged a compromise, and the group has published no proof of the Veradigm claim beyond its own posting.
If the Veradigm claim is accurate, the episode becomes a supply chain problem for the practices that run the vendor’s software, since records held on its platforms could feed downstream breach notices. The mix of Social Security numbers with billing and guarantor data would support long-lived identity fraud if the files are dumped or sold. Trackers caution that leak-site postings are unverified marketing, and groups routinely recycle older data or inflate their hauls.
The Gentlemen has claimed several healthcare targets in recent weeks, including North Carolina’s AnMed network and hospital operator Nutex Health. The listing of Veradigm, one of the larger US health IT names, points to a continued focus on vendors whose patient data reaches far beyond a single hospital.