[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

CYBER WATCH / Supply chain

Veradigm reports patient-data exposure through a vendor's credentials

Veradigm says credentials obtained from a third-party vendor were used to access a limited customer-service interface and copy patient information. BleepingComputer reports that the company has not identified the attacker and says operations were not disrupted. A ransomware group's separate claims about the volume of stolen records remain unverified.

All updates
Reported ReportedPublished Date not recorded

Incident timing: Company filing dated September 8; exact intrusion date not established here.

What is known

BleepingComputer reports that Veradigm disclosed the incident in an SEC filing. Compromised vendor credentials provided access to a limited customer-service API. The company said the stolen information included personal details and, for some patients, Social Security numbers, while clinical information was not affected.

Scope and uncertainty

Veradigm said the credentials did not grant access to its broader network, servers, or databases and that it had not experienced operational disruption. Its investigation was ongoing. A ransomware group separately claimed responsibility and a large record count; the company did not confirm those claims.

Business context

A narrowly scoped third-party integration can still expose sensitive records. Organizations should distinguish what the company's filing establishes from what an extortion actor alleges.

Source & attribution

Read the original reporting at BleepingComputer

AI-assisted summary prepared for Castler editorial review. Evidence labels describe the source of a claim, not a guarantee that every detail of an investigation is settled.

Editorial policy & corrections