Attorneys at Almeida Law Group are investigating whether a class action lawsuit can be filed on behalf of individuals affected by a possible Veradigm data breach. According to dark web monitoring sources, a hacker group calling itself thegentlemen claimed responsibility for a cyberattack on Veradigm in a post first observed in September 2026, alleging it had gained access to internal company systems. As of this writing, Veradigm has not issued a public confirmation of the incident, and the exact scope of any exposed data remains unknown. If you believe you were affected, contact Almeida Law Group.
About Veradigm
Veradigm Inc. (formerly Allscripts, traded on OTC markets as MDRX) is a healthcare technology company founded in 1986 and headquartered in Chicago, Illinois. It provides electronic health records, practice management systems, and patient engagement platforms to healthcare providers, payers, and life sciences organizations, and operates one of the largest multi-EHR data networks in U.S. healthcare. Because Veradigm processes electronic health records and related patient data at significant scale, any compromise of its systems carries heightened risk for the patients whose information flows through its network.
What Happened?
On September 5th, 2026, Ransomware.live reported that the ransomware group known as The Gentlemen posted Veradigm as a claimed victim on its dark web leak site. The attacker claim alleges access to more than 3.5 million patient records containing personally identifiable information, including full names, addresses, Social Security numbers, email addresses, phone numbers, and guarantor PII. These are unverified, attacker-side allegations only. Veradigm has not publicly confirmed this incident, and no independent corroborating source has been found to substantiate the claim. It is not known whether this allegation relates to a prior breach, involves recycled data, or represents an entirely new compromise.
This new claim is separate from a confirmed incident that Veradigm previously disclosed. In December 2024, cybercriminals accessed a Veradigm storage account using stolen credentials, ultimately affecting 2,672,036 individuals. That breach—which exposed names, contact information, dates of birth, health records, health insurance information, payment details, Social Security numbers, and driver’s license numbers—was discovered on July 1st, 2025, and consumer notifications began on September 22nd, 2025. Investigative reporting by DataBreaches.net noted a possible connection between that prior incident and the Rhysida ransomware gang. Veradigm later agreed to pay $10.5 million to settle consolidated class action litigation arising from that 2024 breach, with class members eligible for up to $5,000 in documented losses or an estimated $50 alternative cash payment, plus two years of medical data monitoring. The current September 2026 claim by The Gentlemen is a separate, unconfirmed allegation.
The Gentlemen (tracked by Microsoft as Storm-2697) is a Ransomware-as-a-Service operation that emerged around July 2025, employs dual-extortion tactics combining encryption with data exfiltration and leak threats, and became the most active ransomware group in the second quarter of 2026, having posted approximately 300 claimed victims. The group is assessed with medium-to-high confidence to be operated by Russian-speaking actors and previously operated as ArmCorp, an affiliate of the Qilin RaaS operation.
Key Facts at a Glance
- Company or Organization: Veradigm Inc.
- Industry: Healthcare Technology / Health IT
- Location: Chicago, Illinois, United States
- Incident type: Ransomware leak-site allegation (unverified, attacker-side claim)
- Claim first observed: September 5th, 2026
- Total persons allegedly affected: 3.5+ million (unverified attacker claim)
- Prior breach: December 2024 breach affecting 2,672,036 individuals; discovered July 1st, 2025; notifications began September 22nd, 2025
- Litigation status: $10.5 million class action settlement (Goodrum et al. v. Veradigm Inc.) related to the prior 2024 breach; final approval hearing scheduled for March 18th, 2026
- Source: Ransomware.live – Victim: Veradigm; HIPAA Journal – Veradigm Data Breach; HIPAA Journal – $10.5M Settlement; Microsoft Security Blog – The Gentlemen Ransomware; The Insurer – The Gentlemen Q2 2026
What Should You Do?
If you believe your information may have been exposed—whether in connection with this new unconfirmed allegation or the prior confirmed 2024 breach—there are steps you can take now to protect yourself. Consider placing a free fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion) to make it harder for someone to open new accounts in your name. Monitor your credit reports for unfamiliar accounts or inquiries at AnnualCreditReport.com, where you can access free reports from each bureau. Review your financial account statements regularly for unauthorized transactions. If your health information was involved in the prior confirmed breach, review your Explanation of Benefits statements and check your medical records for services you did not receive. If you experience signs of identity theft, report it at IdentityTheft.gov for step-by-step recovery guidance. Class members from the prior 2024 breach who received settlement notices should also review any identity protection enrollment deadlines in those communications.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.