By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Veradigm Warns of Patient Data Breach After Vendor Attack
Healthcare technology company Veradigm has alerted patients to a data breach that occurred after a cybersecurity incident at one of its third-party vendors, which led to the exposure of personal patient data. The company disclosed this information on May 23, 2024, in a filing with the U.S. Securities and Exchange Commission (SEC). The breach specifically impacted data processed or stored by a vendor that provides services to Veradigm. While Veradigm did not name the specific vendor involved, the incident has raised concerns about the security of patient information within the healthcare technology supply chain. This event follows a claim by the ransomware group Black Basta that it was responsible for the attack, asserting it had exfiltrated approximately 650 gigabytes of sensitive data from Veradigm's systems. Black Basta is known for its double-extortion tactics, which involve both stealing data and encrypting victim systems, threatening to release stolen information if a ransom is not paid. Veradigm stated that it is working with cybersecurity experts and law enforcement to investigate the incident thoroughly. The company has also initiated steps to notify affected individuals and is offering credit monitoring services to those whose personal information may have been compromised. The full extent of the data compromised, including the specific types of personal information and the number of individuals affected, is still under investigation. Veradigm's disclosure highlights the persistent threat of ransomware attacks targeting the healthcare sector, which often holds highly sensitive personal and financial information. The reliance on third-party vendors in the healthcare ecosystem introduces additional layers of risk, as a vulnerability in one vendor's system can have cascading effects on multiple healthcare providers and their patients. The incident underscores the critical need for robust cybersecurity measures and diligent vendor risk management practices within the healthcare industry to protect patient privacy and comply with regulations like HIPAA. Veradigm's stock experienced a decline following the announcement of the breach, reflecting investor concerns about the potential financial and reputational repercussions of the incident. The company has not yet disclosed whether it has paid or intends to pay any ransom to the attackers. The investigation is ongoing, and further details are expected to be released as they become available.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.