Key Facts

Veradigm disclosed in an SEC filing that a third-party vendor cybersecurity incident affected data associated with a small number of its customers. The company says an unauthorized party obtained vendor-environment credentials for an API and used them to download certain patient personal data, including some Social Security numbers.

Technical Details

Veradigm says the compromised credentials provided access only through the limited API interface and did not provide access to its broader network, servers, databases, or other systems. It reports that no clinical or medical data was involved and no operational disruption resulted.

Impact & Mitigation

Veradigm says it initiated incident-response procedures, notified law enforcement, is reviewing the affected data, and is notifying affected customers and individuals with credit monitoring where applicable. Organizations using vendor-connected APIs should review credential scope, access logging, and third-party access controls.

Sources

By Allan