Chicago-based electronic health record vendor Veradigm told federal regulators on September 8 that an intruder used stolen credentials to reach patient information held behind one of its application programming interfaces. The company disclosed the incident in a Securities and Exchange Commission filing, saying the credentials came from the environment of a third-party vendor that provides services to Veradigm customers.
The unauthorized party pulled copies of patient personal data, including Social Security numbers in some cases. Veradigm said no clinical or medical data was involved, access was confined to a single interface, and its broader networks, servers, and databases were untouched. Operations were not disrupted, an investigation continues, and law enforcement has been notified.
The September 8 filing is the company’s first official word since The Gentlemen extortion gang posted Veradigm’s name on its leak site on September 4 and claimed a 3.5-million-patient haul, an assertion the firm, formerly Allscripts, had not previously addressed. The route in fits a pattern that has defined health data theft this year: intruders reaching records through a business associate’s access rather than a direct strike on the records company. Hospitals that outsource patient-facing services should treat every vendor API connection as an extension of their own perimeter and know what the third party can reach.