EHR company Veradigm has disclosed a cybersecurity incident involving one of its third-party vendors.
An unauthorized party obtained credentials from the vendor’s environment and used them to access a Veradigm application programming interface, downloading personal data — including Social Security numbers in some cases — tied to a small number of Veradigm customers, according to a Sept. 8 SEC filing.
No clinical or medical data was involved, per the notice. Veradigm said the compromised credentials only provided access through the limited interface and did not reach the company’s broader network, servers, databases or other systems. The incident caused no operational disruptions, the company said.
Veradigm activated its cybersecurity incident response protocols upon learning of the breach and notified law enforcement. The company is still investigating and reviewing the scope of affected data, and it is notifying affected customers and individuals, offering credit monitoring where applicable.
The disclosure marks at least the second cybersecurity incident Veradigm has reported to customers in the past year, following a 2024 data breach the company began notifying patients about in September 2025.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.