Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data.
The company says the incident did not cause operational disruptions but affected a small number of customers.
Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical practices with electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software.
Thousands of hospitals, clinics, and biopharmaceutical firms across the United States use its solutions.
The company says in a filing with the U.S. Securities and Exchange Commission (SEC) that an attacker obtained credentials from a vendor’s environment for a Veradigm API reserved for customer services. The threat actor then used their access to copy patient data.
Veradigm's disclosure notes that the stolen data includes personal details and Social Security numbers (SSNs) for some of the patients. Clinical or medical information remained safe.
“The vendor’s compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company’s environment, including the Company’s broader network, servers, databases, or other systems,” the company says in the SEC filing.
After discovering the breach, Veradigm initiated its incident-response procedures, notified law enforcement, and is currently investigating to determine the scope.
Affected customers and individuals are being notified, with credit-monitoring services offered where applicable.
The investigation is ongoing, but based on current information, Veradigm does not believe the incident is reasonably likely to materially affect its business, operations, financial condition, or results.
... continue reading