cognitive cybersecurity intelligence

News and Analysis

Search

Veradigm Announces Data Breach Affecting Several Customers

Veradigm Announces Data Breach Affecting Several Customers

On September 22, 2025, Veradigm, a Chicago, Illinois-based provider of practice management and electronic health record solutions to healthcare providers (formerly Allscripts), started issuing notification letters about a July 2025 security incident that involved unauthorized access to customer data.

On July 1, 2025, Veradigm learned that an unauthorized third party had accessed one of its storage locations. Steps were immediately taken to block the unauthorized access, law enforcement was notified, and third-party digital forensics and cybersecurity experts were engaged to investigate the activity and mitigate any impact of the unauthorized access. The investigation determined that a data security incident at one of its customers resulted in credential theft that allowed access to a Veradigm storage account. The attacker used the credentials to access the storage account on or around December 2024. Veradigm learned about the unauthorized access through a third party that was investigating its customer’s security incident. The data breach was limited to the storage account, and no other systems or environments were affected. While data was exposed, Veradigm is unaware of any misuse of the exposed data.

The file review confirmed that the following types of information had been exposed: name, contact information, date of birth, health records information (diagnoses, medications, test results, and treatments), health insurance information, payment details, and limited identifiers, such as Social Security numbers and driver’s license numbers. The types of information involved vary from individual to individual. Veradigm has implemented additional technical safeguards to prevent similar incidents in the future and has offered the affected individuals complimentary credit monitoring and identity theft protection services.

The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected. The data breach affected several of its customers and is likely to be a significant data breach. At least 70,000 individuals have been confirmed as affected in two states alone, based on the breach reports submitted to the Texas and South Carolina state attorneys general. The California Attorney General has also been informed that state residents have been affected.

The post Veradigm Announces Data Breach Affecting Several Customers appeared first on The HIPAA Journal.

Source: www.hipaajournal.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts