Veradigm told the SEC on September 8, 2026 that a vendor's stolen credentials gave an unauthorized party access to a company API. The login came from inside the vendor's own systems, not Veradigm's. The attacker then used it to download data through the API the vendor relied on to deliver services on Veradigm's behalf. The company filed the disclosure as an 8-K under Item 8.01. Veradigm, the Chicago based practice management and EHR company formerly known as Allscripts Healthcare Solutions, said the access reached patient personal data.

The exposure covers identity information. The unauthorized party downloaded personal data on patients, including in some instances Social Security numbers. The filing states that no clinical or medical data was involved, and that the compromised credentials reached only the vendor facing interface. Servers, databases, and the rest of Veradigm's internal systems were never touched, according to the company.

The ransomware group The Gentlemen added Veradigm to its dark web leak site on September 5, 2026, three days before the SEC filing, claiming 3.5 million patient records. Veradigm has not confirmed that number in its disclosure. The gap between an extortion group's claimed count and a company's own accounting keeps showing up in these filings, and it leaves customers guessing at the real scope until a lawsuit or a state attorney general forces a fuller count.

Veradigm activated its incident response protocols, notified law enforcement, and is notifying affected customers and individuals while offering credit monitoring where applicable. The company says it does not believe the incident is reasonably likely to have a material impact on its business, operations, financial condition, or results of operations, though it has not yet determined the extent of any liabilities. A vendor's stolen credentials are still a company's exposure. The API access list is where that risk actually sits, and few companies audit who holds a key to it until a filing like this one forces the question.