Veradigm LLC
ent_019e1096f54fe9c4888fbeadd00d7fbc
Disclosures
13
SEC 8-K · Leak Site · State AG · HHS OCR · 11 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
2,672,036
nationwide · State AG TX
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Veradigm LLC
- Normalized
- veradigm— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300CX6JO63C556L49
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (13)newest first
- FEDERALSEC 8-Kas victim2026-09-08
Veradigm Inc. disclosed a cybersecurity incident involving a third-party vendor. An unauthorized party obtained credentials from the vendor's environment to access a specific API used to serve Veradigm's customers. The attacker used these credentials to download copies of certain patient personal data, including, in some instances, Social Security numbers. No clinical or medical data was involved. Veradigm notified law enforcement, is reviewing affected data, and is notifying customers, offering credit monitoring where applicable. The incident did not cause operational disruptions.
- GLOBALLeak Siteas victim2026-09-04
veradigm.com zoominfo.com/c/veradigm-llc/471134180 3.5+ million personal patient records with PII full name, address, social security number, email, address, phone number,guarantors PII ,Score Veradigm Inc. is a publicly traded American healthcare technology and data analytics company (OTC: MDRX), the former Allscripts, founded in 1986 and renamed Veradigm in January 2023, headquartered in Chicago with about 2,300–2,600 employees. Its core asset is one of the largest multi-EHR data networks in US healthcare — over 450,000 connected providers and 200M+ patient records — which it monetizes through three segments: Provider (EHR, practice management, revenue cycle: $473M in 2024), Payer (quality and risk adjustment analytics: $67.3M) and Life Sciences (real-world data and AI-driven evidence: $54M).
- Texas State AGas victim2025-12-19
Veradigm LLC based in Chicago, Illinois, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-07-01 and reported on 2025-12-19. 43,684 Texas residents were affected. 2,672,036 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Medical Information;Health Insurance Information;Other;Date of Birth. Consumers were notified via U.S. Mail.
- California State AGas victim2025-12-18
Veradigm LLC reported a data security breach to the California AG involving unauthorized access to a storage account, with a breach date of December 15, 2024. The notice, dated September 22, 2025, indicates that personal data of affected individuals was potentially exposed. Veradigm engaged cybersecurity experts, implemented new technical safeguards, and offered 12–24 months of complimentary Experian IdentityWorks credit monitoring to affected individuals.
- Washington State AGas victim2025-12-02
Veradigm LLC reported an unauthorized access incident affecting customer data. The breach occurred between Dec 15-16, 2024, and was discovered on July 1, 2025. 845 Washington residents were affected. Data included names, SSNs, and financial account numbers. Veradigm engaged forensic experts, implemented technical safeguards, and offered credit monitoring.
- Oregon State AGas victim2025-12-02
Veradigm LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2025-12-02. The breach occurred during 12/15/2024 - 12/16/2024. The breach was discovered on 7/1/2025. 2,672,036 individuals were affected. Notice was sent on 9/22/202511/10/202512/2/2025.
- Illinois State AGas victim2025-11-01
VERADIGM LLC filed a data-breach notice with the Illinois Attorney General in November 2025 (case 25-11-585). The register records the breach as discovered on July 1, 2025. Personal information types reported: medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- South Carolina State AGas victim2025-09-22
Veradigm LLC notified South Carolina and other state attorneys general of a security incident involving unauthorized access to a cloud storage account. The breach potentially exposed personal data, including names and Social Security numbers, of individuals. Veradigm engaged cybersecurity experts, implemented technical safeguards, and is offering complimentary credit monitoring and identity protection services through Experian IdentityWorks to affected individuals.
- Massachusetts State AGas victim2025-09-22
Veradigm LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-09-22. 362 Massachusetts residents were affected.
- Montana State AGas victim2025-09-22
Veradigm LLC notified Montana residents of a cybersecurity incident involving unauthorized access to a storage account. The breach potentially exposed personal data including names and Social Security numbers. Veradigm engaged cybersecurity experts, implemented new safeguards, and is offering complimentary credit monitoring and identity protection services through Experian IdentityWorks.
- Vermont State AGas victim2025-09-22
Veradigm notified consumers of a data breach involving unauthorized access to a storage account. The incident potentially exposed personal information including names and financial account numbers. Veradigm engaged cybersecurity experts, implemented new technical safeguards, and offered complimentary credit monitoring and identity protection services through Experian IdentityWorks to affected individuals.
- ILLINOISHHS OCRas victim2025-09-22
HHS OCR breach portal entry: Veradigm LLC (IL), reporting as a Business Associate, disclosed a Hacking/IT Incident affecting a Network Server. The breach was submitted on 2025-09-22 and is reported as affecting 2,672,036 individuals. The portal row contains no narrative description of the attack vector, threat actor, data types beyond 'Network Server' location, dates of occurrence, or remediation.
- California State AGas victim2025-09-22
Veradigm LLC reported a cybersecurity incident on December 15, 2025, involving unauthorized access to a storage account. The breach potentially exposed personal data including names and Social Security numbers. Veradigm engaged cybersecurity experts, implemented new safeguards, and is offering credit monitoring services to affected individuals.
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of Veradigm LLC — not by Veradigm LLC itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.