news.mlab.sh
Back to the feed
threat-intel

Electronic health record company says customer data stolen in breach

High
Summary

Veradigm, an electronic health record company, disclosed that hackers gained access to a vendor’s systems, leading to the theft of customer data including Social Security numbers. The breach, linked to the Gentleman ransomware gang, impacted approximately 3.5 million patients and has caused operational disruptions for Veradigm and Boston Scientific. This follows a pattern of cybersecurity incidents targeting healthcare data firms this year, highlighting a significant and ongoing threat to patient data.

Veradigm, a Chicago-based electronic health record company, informed regulators on Tuesday that hackers had infiltrated a vendor’s systems, resulting in the theft of customer data, including Social Security numbers. The incident is linked to the Gentleman ransomware gang, who added Veradigm to their leak site on Friday, claiming to have stolen health records of 3.5 million patients. Veradigm provides health record technology and management systems to thousands of hospitals and doctors globally, generating $594 million in revenue in 2024. The breach occurred after an unauthorized party obtained credentials from the vendor’s environment and used them to download patient data through a Veradigm application programming interface. Veradigm emphasized that the access was limited to a specific interface and did not affect its broader network infrastructure, including servers and databases. Despite this, the incident has caused operational disruptions for Veradigm and medical device giant Boston Scientific, who have had to undergo a “substantial restoration of its distribution network.” Boston Scientific confirmed that the cyberattack, initially announced in December, continues to cause operational issues and is likely to impact its financial performance, preventing the company from meeting its net sales targets for the quarter. This incident follows a trend of similar attacks against healthcare data firms this year, including breaches at Aesto (9 million records) and CareCloud (3.7 million records). The Gentleman ransomware gang has been active since last fall, targeting healthcare companies like Nutex and AnMed.

Read the full article at The Record