Incident timing: Company filing dated September 8; exact intrusion date not established here.
What is known
BleepingComputer reports that Veradigm disclosed the incident in an SEC filing. Compromised vendor credentials provided access to a limited customer-service API. The company said the stolen information included personal details and, for some patients, Social Security numbers, while clinical information was not affected.
Scope and uncertainty
Veradigm said the credentials did not grant access to its broader network, servers, or databases and that it had not experienced operational disruption. Its investigation was ongoing. A ransomware group separately claimed responsibility and a large record count; the company did not confirm those claims.
Business context
A narrowly scoped third-party integration can still expose sensitive records. Organizations should distinguish what the company's filing establishes from what an extortion actor alleges.
Source & attribution
Read the original reporting at BleepingComputerAI-assisted summary prepared for Castler editorial review. Evidence labels describe the source of a claim, not a guarantee that every detail of an investigation is settled.