|

Veradigm Data Breach 2026, Vendor Hack Exposes Patient Data, Two Class Action Lawsuits Filed

Veradigm, the Chicago health technology company formerly known as Allscripts, told the SEC on September 8, 2026 that an unauthorized party used credentials stolen from a third-party vendor to download patient personal data, including Social Security numbers in some cases. The company says no clinical or medical data was involved and that only a small number of its customers were affected. It has not said how many people that means. A ransomware group claims it holds 3.5 million records, but that figure comes from the attackers and has not been confirmed.

Two putative class actions were filed within a day of the disclosure: Clay v. Veradigm, Inc., No. 1:26-cv-10827, and Walker v. Veradigm, Inc., No. 1:26-cv-10852, both in the U.S. District Court for the Northern District of Illinois.

There is no settlement, no claim form and no claim deadline for this incident. No class has been certified, and Veradigm has not been found liable. This incident is also separate from Veradigm’s earlier data breach, which led to a $10.5 million settlement. That settlement does not cover this one.

Veradigm Data Breach: Quick Facts

DetailWhat is known
CompanyVeradigm Inc. (formerly Allscripts Healthcare Solutions), Chicago, Illinois
DisclosedSeptember 8, 2026, in an SEC Form 8-K (Item 8.01)
How it happenedCredentials taken from a third-party vendor’s environment were used to access a Veradigm application programming interface (API)
Data involved, per VeradigmPatient personal information, and in some instances Social Security numbers. Veradigm says no clinical or medical data
People affectedNot disclosed by Veradigm. The Gentlemen ransomware group claims 3.5 million records (unverified)
Vendor namedNo
Wider network accessed?Veradigm says no. Access was limited to the vendor’s interface
Operational disruptionNone, per Veradigm
Credit monitoringOffered “where applicable,” per the 8-K
LawsuitsClay v. Veradigm (filed September 8, 2026) and Walker v. Veradigm (filed September 9, 2026), both in the Northern District of Illinois
Settlement or claim formNone. No class has been certified
Official sourceVeradigm’s Form 8-K filed with the SEC on September 8, 2026 (listed in Sources)

What Happened in the Veradigm Data Breach?

Veradigm’s Form 8-K says the company “recently learned” that one of its vendors had a cybersecurity incident. An unauthorized party obtained credentials from that vendor’s environment for a Veradigm API, which is the connection the vendor used to provide services on behalf of Veradigm’s customers. According to the filing, the intruder used those credentials to download copies of certain patient personal data, in some cases including Social Security numbers.

Veradigm says the stolen credentials opened only that one interface and did not give access to its broader network, servers or databases. In plain terms, the company is saying the attackers did not break into its main systems. They used a side door that a vendor already held the key to.

The company says it started its incident response procedures, notified law enforcement and is still investigating. It is reviewing the affected data and notifying affected customers and individuals. Veradigm also says it has not yet determined what liability the incident may bring but does not expect a material impact on its business or finances.

What the filing leaves out matters just as much. It does not name the vendor, give a number of affected people, say when the intrusion began, or list which customers were affected.

Why vendor breaches are a recurring risk

An API lets different software systems exchange information. Healthcare organizations rely on outside vendors for many tasks that touch patient data, so a security failure at a vendor can expose data even when the main company says its own systems stayed protected. That is why regulators and courts look closely at how companies choose, monitor and limit access for their vendors.

Related article: Veradigm $10.5 million settlement And WebTPA data breach settlement

What Patient Information Was Exposed?

Veradigm says the downloaded information included patients’ personal data, with Social Security numbers included in some instances. It has not published a complete list of data fields or said that every affected person had the same information taken.

The difference matters. A person whose name and contact details were exposed faces different risks from a person whose Social Security number was also exposed, because criminals can use a Social Security number with other details to open accounts, impersonate victims or commit identity fraud.

The complaints allege the stolen data included names, Social Security numbers, phone numbers and medical information. Veradigm says no clinical or medical data was involved. That conflict is unresolved. Your own notice letter is the best guide to what applies to you.

What Is Still Unconfirmed?

Veradigm’s account and the lawsuits do not line up on every point.

QuestionVeradigm’s 8-KLawsuits and reporting
Was medical information taken?No clinical or medical data involvedBoth complaints allege “medical information” was compromised
When did it happen?Not statedComplaints say on or around September 5, 2026, on information and belief
How many people?A “small number” of customersThe Gentlemen claims 3.5 million patient records
Who did it?Attacker not namedComplaints say The Gentlemen claimed responsibility
Was the data published?Not addressedBoth named plaintiffs allege their names and Social Security numbers appeared on the dark web

One caution: the Clay complaint was filed the same day as the 8-K, and both complaints rely on “information and belief” and threat-intelligence reporting for incident details. They are fast-written allegations, not findings.

Veradigm Data Breach 2026, Vendor Hack Exposes Patient Data, Two Class Action Lawsuits Filed

The Gentlemen Ransomware Group’s Claim

Security reporting says The Gentlemen, a ransomware group that runs double-extortion attacks, listed Veradigm on its leak site on September 5, 2026. The group claims it holds 3.5 million patient records covering names, home addresses, Social Security numbers, emails, phone numbers and guarantor information. It reportedly set a September 11 deadline to publish the data unless Veradigm negotiated.

Veradigm’s filing does not mention ransomware or name any group. No independent confirmation of the 3.5 million figure, or of what if anything was published, was found in the sources reviewed. A leak-site number is the attacker’s own claim, designed to pressure the victim, so it should be treated as a claim and not a count.

Veradigm Data Breach Lawsuits: Clay v. Veradigm and Walker v. Veradigm

Two putative class actions are pending in the U.S. District Court for the Northern District of Illinois, Eastern Division. They are nearly identical.

DetailClay v. Veradigm, Inc.Walker v. Veradigm, Inc.
Case number1:26-cv-108271:26-cv-10852
FiledSeptember 8, 2026September 9, 2026
PlaintiffTodd Clay of Mount Pleasant, North Carolina, a former patient of a Veradigm clientTanya Walker of Mars Hill, North Carolina, a patient of a Veradigm client
Plaintiff’s counselMilberg, PLLCKopelowitz Ostrow P.A.
Proposed classNationwide: everyone whose private information was accessed or acquired in the breachSame
ClaimsNegligence; negligence per se; breach of third-party beneficiary contract; unjust enrichment; declaratory judgmentSame five

Both complaints say Veradigm did not use reasonable security, did not monitor its systems well enough to catch the intrusion sooner, and did not promptly notify the people affected. The negligence per se count rests on Section 5 of the FTC Act and HIPAA. The contract count says Veradigm’s agreements with its customers were meant to protect patients, who sue as intended third-party beneficiaries.

The plaintiffs ask for damages, restitution, lifetime credit monitoring and identity theft insurance, and a court order forcing Veradigm to change its security practices, including outside audits and tighter segmentation of its systems. They also seek attorneys’ fees and the cost of notifying class members.

What this means right now. These are allegations in putative class actions. No judge has certified a class, and Veradigm has not been found liable. There is no claim form, so there is nothing for patients to file. No consolidation order was found in the sources reviewed, although plaintiffs’ lawyers often ask a court to consolidate near-identical suits in the same district.

What Laws Apply to a Healthcare Vendor Data Breach?

Several laws may be relevant, depending on which organizations held the data, their legal roles and what data was involved. These are legal context, not findings that Veradigm or its vendor violated any requirement.

HIPAA and the Breach Notification Rule

HIPAA imposes privacy and security requirements on covered entities (such as providers and health plans) and on their business associates, which can include health technology vendors. The Breach Notification Rule (45 C.F.R. sections 164.400 to 164.414) generally requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured protected health information. It also requires notice to the U.S. Department of Health and Human Services, and to the media for larger breaches, and it requires business associates to notify the covered entity. Whether HIPAA applies to a particular piece of data depends on whether it is protected health information, and Veradigm says no clinical or medical data was involved here.

HIPAA does not give individuals a right to sue. That is why the complaints use HIPAA as a standard of care within a negligence per se theory, a theory that defendants often challenge.

State data breach notification laws

All 50 states have laws requiring businesses to notify residents when specified personal information, typically including a name plus a Social Security number, is accessed without authorization. Deadlines, covered data and rules for notifying state attorneys general vary. Illinois, where Veradigm is based, has the Personal Information Protection Act (815 ILCS 530), which requires notice to affected Illinois residents and, for larger breaches, to the Illinois Attorney General. Because Veradigm has not said whose data was taken, it is not possible to say which state’s law applies to which person. Follow the instructions in your own notice.

Federal Trade Commission Act

Section 5 of the FTC Act (15 U.S.C. section 45) prohibits unfair or deceptive acts or practices. The FTC has used it against companies with inadequate data security. A breach alone does not establish a violation.

SEC disclosure rules

Veradigm disclosed the incident in a Form 8-K under Item 8.01, the item for other events a company chooses to report. SEC rules separately require public companies to disclose material cybersecurity incidents under Item 1.05. The company said it does not expect a material impact, which fits its use of Item 8.01, but how the incident is classified could change as the investigation continues.

Negligence and standing in class actions

To win a negligence claim, plaintiffs generally must show a duty, a breach of that duty, causation and damages. In federal court, plaintiffs must also show a concrete injury to have standing, a requirement the Supreme Court emphasized in TransUnion LLC v. Ramirez (2021). The Seventh Circuit, which covers Illinois, has previously held that the risk of future identity theft after a data breach can support standing in some circumstances, including in Remijas v. Neiman Marcus Group (2015). Whether that applies here will depend on what the plaintiffs can show, such as evidence that data was actually misused or published.

Class certification is governed by Federal Rule of Civil Procedure 23, which requires, among other things, common questions, typical claims and adequate representatives. Courts can consolidate related cases under Rule 42(a).

Who May Be Affected?

You may be in this group without ever having heard of Veradigm. The company sells software and data services to healthcare providers, health plans and life sciences companies, so patients usually deal with the provider, not with Veradigm. The 8-K says a small number of those customers were affected.

The clearest sign you are included is a breach notice from Veradigm, or from your own provider or health plan. The notice should say what information was involved. Do not assume your provider was affected just because it uses Veradigm products.

What to Do If Your Information May Be Part of the Breach

  1. Look for the notice. It will come from Veradigm, or from your provider or plan. Do not confirm personal details to anyone who calls or texts you about the breach.
  2. Check whether your Social Security number was involved. The company says it was included in some cases, not all.
  3. Read the credit monitoring offer. Veradigm says monitoring is offered where applicable. Check the terms before you enroll.
  4. Freeze your credit. A free security freeze at Equifax, Experian and TransUnion blocks new accounts from being opened in your name. Federal law makes freezes free.
  5. Review your credit reports for accounts you do not recognize, using AnnualCreditReport.com.
  6. Check your health paperwork. Review explanation of benefits statements and medical bills for services you never received.
  7. Expect phishing. Scammers use breach headlines. Do not click links or give sensitive information in an unexpected message, even if it mentions Veradigm or your provider. Contact the organization using a phone number or website you find on your own.
  8. Keep records. Save your notice and any correspondence. If someone misuses your information, report it at the FTC’s IdentityTheft.gov and keep receipts and a record of time and money spent fixing it.
  9. Ask your provider. If you think your provider uses Veradigm services, ask it through its official contact details whether its patients were affected.

Veradigm’s Earlier Data Breach and $10.5 Million Settlement Are a Separate Case

Do not confuse this incident with Veradigm’s earlier breach. That incident involved unauthorized access to an isolated cloud storage account used for data migrations. Veradigm said the access occurred in the fourth quarter of 2024 and that it learned of it in July 2025. The account held backup copies of data tied to some customers, including protected health information.

That earlier incident led to Goodrum, et al. v. Veradigm, Inc., No. 1:25-cv-07062 (N.D. Ill.), which settled for $10.5 million. The class covered people who were sent notice of the earlier incident, and the claim deadline was March 3, 2026. The settlement website’s June 12, 2026 update said approved claim payments had been issued and that uncashed checks would become void after September 10, 2026.

That settlement resolves the earlier incident only. It does not cover the September 2026 incident, its claim deadline has passed, and a Goodrum claim does not apply here. The existence of the earlier settlement does not mean anyone affected by the new incident qualifies for a payment.

Timeline of the Veradigm Data Breach and Lawsuits

DateEvent
Q4 2024Earlier, separate Veradigm cloud storage incident (later settled in Goodrum for $10.5 million)
September 5, 2026The Gentlemen lists Veradigm on its leak site (per security reporting). The complaints allege the incident occurred on or around this date
September 8, 2026Veradigm files its Form 8-K. Clay v. Veradigm is filed the same day
September 9, 2026Walker v. Veradigm is filed
September 10, 2026Uncashed checks in the earlier Goodrum settlement become void
September 11, 2026Reported deadline The Gentlemen set to publish the data
October 9, 2026No settlement, certified class or consolidation order found in the sources reviewed. Veradigm had not published an affected-person count

What Happens Next?

The key open questions are how many people were affected, exactly what information was taken, whether more notices will go out, whether the two lawsuits will be consolidated, and how Veradigm responds to the complaints. A typical sequence in cases like this is consolidation, appointment of lead counsel, a consolidated complaint, a motion to dismiss and, if the case survives, discovery and a class certification motion. Many data breach class actions eventually settle, but nothing in the public record shows that is happening here.

This article will need updating if a settlement, consolidation order or new regulatory action is announced.

Frequently Asked Questions

What happened in the Veradigm data breach?

Veradigm told the SEC on September 8, 2026 that an unauthorized party used credentials stolen from a third-party vendor to access a Veradigm API and download patient data tied to a small number of its customers.

Was my Social Security number exposed?

Veradigm says Social Security numbers were included in some instances. It has not said whose. Your notice letter is the only reliable way to find out what applies to you.

Did the breach expose medical records?

Veradigm says no clinical or medical data was involved. The two lawsuits allege medical information was taken. That conflict is unresolved.

How many people were affected?

Veradigm has not given a number. The Gentlemen claims 3.5 million records, and that claim is unverified.

Why would a Veradigm breach affect me if I never used Veradigm?

Veradigm works for providers, health plans and life sciences companies. Your data can sit with Veradigm because a provider or plan you use is its customer.

Can I join the Veradigm data breach lawsuit or get money?

Not yet. Both cases are at the complaint stage as putative class actions. No class is certified, and there is no settlement or claim process.

Does the $10.5 million Veradigm settlement cover this breach?

No. That settlement resolves Goodrum v. Veradigm over an earlier incident. This September 2026 incident is separate.

Is Veradigm offering credit monitoring?

The 8-K says credit monitoring is being offered where applicable. Eligibility depends on your notice.

Should I freeze my credit?

If a notice tells you your Social Security number was involved, a credit freeze is a sensible step. Freezes at the three major bureaus are free.

Did hackers access Veradigm’s entire network?

Veradigm says no. It says the stolen credentials gave access only through a limited vendor interface and not to its broader network, servers or databases.

Was Veradigm hit by ransomware?

Veradigm’s filing does not say so. A ransomware group called The Gentlemen claims responsibility, but that claim has not been confirmed by the company.

Bottom Line

Veradigm says a vendor’s stolen credentials let an intruder download patient personal data, in some cases including Social Security numbers, through a limited API. The company says no clinical or medical data was involved and that only a small number of customers were affected, while a ransomware group claims 3.5 million records and two class action lawsuits allege medical information was taken. Those accounts conflict, and the real scope is not yet known.

There is no settlement, claim form or deadline for this incident, and the earlier $10.5 million settlement does not cover it. If you get a breach notice, read it, consider a free credit freeze if your Social Security number was involved, watch for phishing and keep your records.

Sources and Verification

Primary sources

  • Veradigm Inc., Form 8-K, Item 8.01, filed September 8, 2026: https://www.sec.gov/Archives/edgar/data/0001124804/000119312526385249/mdrx-20260908.htm
  • Class Action Complaint, Clay v. Veradigm, Inc., No. 1:26-cv-10827 (N.D. Ill. filed Sept. 8, 2026): https://storage.courtlistener.com/recap/gov.uscourts.ilnd.507387/gov.uscourts.ilnd.507387.1.0.pdf
  • Docket, Clay v. Veradigm, Inc.: https://www.courtlistener.com/docket/74760713/clay-v-veradigm-inc/
  • Class Action Complaint, Walker v. Veradigm, Inc., No. 1:26-cv-10852 (N.D. Ill. filed Sept. 9, 2026): https://storage.courtlistener.com/recap/gov.uscourts.ilnd.507426/gov.uscourts.ilnd.507426.1.0.pdf
  • Official website for the earlier Goodrum v. Veradigm settlement: https://www.veradigmdatasettlement.com/
  • Kroll Settlement Administration statement, Goodrum, et al. v. Veradigm, Inc. (Nov. 26, 2025): https://www.prnewswire.com/news-releases/if-you-were-sent-notice-that-your-private-information-may-have-been-impacted-as-a-result-of-the-veradigm-inc-data-incident-you-are-eligible-to-receive-a-settlement-class-member-benefit-from-a-class-action-settlement-302626214.html

Security and industry reporting

  • Security Magazine, “Healthcare Tech Company Veradigm Exposed in Third-Party Breach,” Sept. 9, 2026: https://www.securitymagazine.com/articles/102564-healthcare-tech-company-veradigm-exposed-in-third-party-breach
  • teiss, “Veradigm discloses data breach after vendor’s systems compromised”: https://www.teiss.co.uk/news/veradigm-discloses-data-breach-after-vendors-systems-compromised-18112
  • Becker’s Hospital Review, “Veradigm discloses cybersecurity incident tied to vendor”: https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/veradigm-discloses-cybersecurity-incident-tied-to-vendor/
  • Healthcare IT News, “Veradigm reports third-party vendor cyberattack”: https://www.healthcareitnews.com/news/veradigm-reports-third-party-vendor-cyberattack

Legal and government sources

  • HIPAA Breach Notification Rule, 45 C.F.R. sections 164.400 to 164.414; U.S. Department of Health and Human Services HIPAA resources: https://www.hhs.gov/hipaa/for-professionals/index.html
  • Federal Trade Commission Act, Section 5, 15 U.S.C. section 45: https://www.ftc.gov/legal-library/browse/statutes/federal-trade-commission-act
  • Federal Trade Commission identity theft guidance: https://www.identitytheft.gov/
  • AnnualCreditReport.com: https://www.annualcreditreport.com/
  • Illinois Personal Information Protection Act, 815 ILCS 530
  • Federal Rules of Civil Procedure 23 and 42(a)
  • TransUnion LLC v. Ramirez, 594 U.S. 413 (2021); Remijas v. Neiman Marcus Group, LLC, 794 F.3d 688 (7th Cir. 2015)

Not verified: the number of people affected, the identity of the vendor, the dates of access, whether any data was actually published, and whether the Clay and Walker cases have been consolidated.

Disclaimer: This article is for general information only and is not legal advice. The author is a legal content researcher, not a practicing attorney. The investigation is ongoing and details may change. Consult a qualified attorney about your own situation.

By Israr Ahmad, Founder and Legal Content Researcher, AllAboutLawyer.com

About the Author

Israr Ahmad is a legal content researcher with 4+ years of experience covering class action settlements and consumer rights cases. He has researched and published coverage of 2,500+ settlements using verified court records, settlement administrator filings, and government sources. Learn more about Israr.

Leave a Reply

Your email address will not be published. Required fields are marked *