Veradigm Inc. disclosed a cybersecurity incident
What the company disclosed
Veradigm Inc. (the "Company") recently learned that one of its third-party vendors experienced a cybersecurity incident that impacted certain data associated with a small number of the Company's customers. Based on the Company's investigation to date, an unauthorized party obtained credentials from the vendor's environment to a Company application programming interface used by the vendor to provide services on behalf of the Company's customers. The unauthorized party used these credentials to download copies of certain personal data of patients, including, in some instances, Social Security numbers; no clinical or medical data was involved. The vendor's compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company's environment, including the Company's broader network, servers, databases, or other systems. The incident did not result in any operational disruptions. The Company promptly initiated its cybersecurity incident response protocols upon learning of the incident and has notified law enforcement. The Company's investigation is ongoing. The Company is reviewing the affected data, and affected customers and individuals are being notified, with credit monitoring services being offered where applicable. The Company has not yet determined the extent of any potential liabilities associated with this matter. However, based on the information currently available, the Company does not believe that this incident is reasonably likely to have a material impact on the Company's business, operations, financial condition, or results of operations. This Current Report on Form 8-K contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. These forward-looking statements are based on the current beliefs and expectations of the Company with respect to the cybersecurity incident and its impact on the Company's business, operations and financial results, only speak as of the date that they are made, and are subject to significant risks and uncertainties. Such statements can be identified by the use of words such as "future," "anticipates," "believes," "estimates," "expects," "intends," "plans," "predicts," "will," "would," "could," "continue," "can," "may," "look forward," "aims," "hopes," and "seeks" and similar terms, although not all forward-looking statements contain such words or expressions. Actual results could differ significantly from those set forth in the forward-looking statements. Important factors that may cause actual results to differ materially from those in the forward-looking statements include, but are not limited to, legal, reputational, and financial risks resulting from the cybersecurity incident, including any related regulatory inquiries, litigation, or remediation costs, and other factors contained in "Part 1, Item 1A. "Risk Factors" in the Company's Annual Report on Form 10-K for each of the fiscal years ended December 31, 2024 and December 31, 2023, and the Company's other filings with the SEC from time to time. The Company does not undertake to update any forward-looking statements to reflect changed assumptions, the impact of circumstances or events that may arise after the date of the forward-looking statements, or other changes over time, except as required by law.
Quoted from the company’s own Form 8-K, Item 1.05, as filed with the US Securities and Exchange Commission. SEC filings are works of the US federal government and are in the public domain.
The record
- Organisation
- Veradigm Inc. →
- Identity
- Veradigm Inc.identified by its SEC Central Index Key (0001124804)
- Records affected
- Records not disclosed
- Sector
- Services-Computer Integrated Systems DesignSIC 7373, from the company’s own filing
- Occurred
- Not disclosed
- Disclosed
- 2026-09-08
- First recorded here
- 2026-09-16
Sources (1)
One source so far.
- SEC EDGAR ↗First reported
2026-09-08