Veradigm discloses cybersecurity incident tied to vendor

Advertisement

EHR company Veradigm has disclosed a cybersecurity incident involving one of its third-party vendors.

An unauthorized party obtained credentials from the vendor’s environment and used them to access a Veradigm application programming interface, downloading personal data — including Social Security numbers in some cases — tied to a small number of Veradigm customers, according to a Sept. 8 SEC filing.

No clinical or medical data was involved, per the notice. Veradigm said the compromised credentials only provided access through the limited interface and did not reach the company’s broader network, servers, databases or other systems. The incident caused no operational disruptions, the company said.

Veradigm activated its cybersecurity incident response protocols upon learning of the breach and notified law enforcement. The company is still investigating and reviewing the scope of affected data, and it is notifying affected customers and individuals, offering credit monitoring where applicable.

The disclosure marks at least the second cybersecurity incident Veradigm has reported to customers in the past year, following a 2024 data breach the company began notifying patients about in September 2025.

Advertisement

Next Up in Cybersecurity

Advertisement