Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data

The Chicago, Illinois-based practice management and electronic health record company Veradigm (formerly Allscripts Healthcare Solutions) has disclosed a cybersecurity incident in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC).

According to the September 8, 2026, filing, Veradigm recently learned that one of its third-party vendors had experienced a cybersecurity incident that impacted a small number of Veradigm’s customers. Veradigm explained that a threat actor obtained credentials from the vendor’s environment for a Veradigm Application Programming Interface (API) used for customer services. The threat actor was able to use the access to copy patient data.

The threat actor only had access to the API, and no other parts of its network were compromised, including servers, databases, or other systems. Veradigm determined that data stolen in the incident included the personal information of patients, which for certain patients may have involved their Social Security numbers; however, the company has determined that clinical and medical information was not involved and remained secure. As a precaution against data misuse, Veradigm is offering the affected individuals complimentary credit monitoring services.

The investigation is ongoing, and Veradigm has yet to publicly disclose how many individuals have been affected. The company said the incident did not impact its operations, and while the extent of any potential liabilities associated with the incident has not yet been determined, the company does not believe the incident is reasonably likely to have a material impact on the company’s business, operations, financial condition, or results of operations.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Veradigm did not disclose the name of the threat actor behind the attack, which appears to be a prolific threat group called The Gentlemen. The Gentlemen added Veradigm to its dark web data leak site on September 5, 2026. The posting alleges that data exfiltrated in the attack includes names, addresses, phone numbers, email addresses, and other personally identifiable information, and that 3.5 million patient records have been obtained. A threat has been issued to publish the stolen data if the ransom is not paid.

The post Veradigm Discloses Third Party Data Breach as Hackers Threaten to Publish Data appeared first on The HIPAA Journal.

Palomar Health Medical Group; Summit Medical Group Settle Data Breach Lawsuits

Settlements have been reached to resolve class action data breach lawsuits against Palomar Health Medical Group in California and Summit Medical Group in Tennessee.

Palomar Health Medical Group Data Breach Settlement

Palomar Health Medical Group, a non-profit healthcare organization serving patients at 20 locations in North San Diego County and South Riverside County in Southern California, has agreed to settle class action litigation stemming from a Spring 2024 cybersecurity incident involving the protected health information of 1,140,221 individuals. The incident was identified on May 5, 2024, and the forensic investigation confirmed that hackers had access to its network from April 23, 2024, to May 5, 2024. Data potentially stolen in the incident included names, contact information, dates of birth, Social Security numbers, driver’s license numbers, state identification numbers, medical histories, health information, health insurance information, and other sensitive data.

Several class action lawsuits were filed in response to the data breach, all of which alleged that the data breach could have been prevented and occurred as a result of the failure of the defendant to implement reasonable and appropriate cybersecurity measures. On September 16, 2024, the lawsuits were consolidated into a single complaint – Castro et al. v. Arch Health Partners, Inc. d/b/a Palomar Health Medical Group – which is pending in the Superior Court for the State of California, County of San Diego. The consolidated lawsuit asserted claims for negligence, negligence per se, invasion of privacy, and violations of the California Consumer Privacy Act, California Confidentiality of Medical Information Act, and California Customer Records Act. All claims and contentions in the lawsuit were denied by Palomar Health Medical Group; however, all parties agreed to settle the litigation to avoid the costs and risks associated with continued litigation.

Under the terms of the settlement, Palomar Health Medical Group has agreed to establish a $3,100,000 settlement fund, from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives will be deducted. The remainder of the settlement fund will be used to pay benefits to the class members.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The settlement provides two years of complimentary single-bureau credit monitoring services to all class members. Class members may also claim one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses up to $5,000 per class member, or a claim may be submitted for an alternative pro rata cash payment, estimated to be $60 per class member. The deadline for opting out and objecting to the settlement is October 7, 2026. Claims must be submitted by October 22, 2026, and the final fairness hearing has been scheduled for November 6, 2026.

Summit Medical Group Data Breach Settlement

Summit Medical Group, a Tennessee-based medical group with more than 90 locations in Tennessee, has settled class action litigation stemming from a November 2024 cybersecurity incident that exposed the personal and protected health information of more than 464,000 patients and employees. Data exposed in the incident included names, contact information, demographic information, medical record numbers, provider names, dates of services, facilities of service, treatment information, and/or health insurance information. The affected individuals were notified about the breach in March 2025.

Three putative class action lawsuits were filed in response to the data breach. The lawsuits had overlapping claims and putative classes, and were consolidated into a single lawsuit – Harris, et al. v. Summit Medical Group, PLLC, which is pending in the Circuit Court for Knox County, Tennessee. The consolidated lawsuit alleged that the data breach occurred as a result of insufficient security measures, and despite determining on September 19, 2024, that patient data was exposed, notifications were not mailed until March 2025. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, breach of fiduciary duty, unjust enrichment, and invasion of privacy, all of which were denied by Summit Medical Group. Summit Medical Group sought to have the lawsuit dismissed; however, after considering the time, cost, and risks associated with continued litigation, all parties agreed to settle the litigation. The terms of the settlement have been finalized, and the proposed settlement has received preliminary approval from the court.

The settlement provides two years of medical data monitoring with the CyEx Medical Shield Complete service. In addition, class members may submit a claim for reimbursement of documented out-of-pocket losses due to the data breach up to a maximum of $2,500 per class member. A claim may also be submitted for reimbursement of up to three hours of lost time at $15 per hour (max $45). The cash payments have been capped at $500,000. Claims will be paid pro rata if claims exceed that total.

Summit Medical Group has also agreed to pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. The deadline for objecting to the settlement and exclusion is October 10, 2026. Claims must be submitted by November 4, 2026, and the final fairness hearing has been scheduled for November 19, 2026.

The post Palomar Health Medical Group; Summit Medical Group Settle Data Breach Lawsuits appeared first on The HIPAA Journal.

FBI Raises Alarm About OAuth Consent Phishing Activity

The Federal Bureau of Investigation (FBI) has issued a warning about ongoing phishing activity involving a sophisticated technique known as OAuth consent phishing. Since late 2025, the FBI has observed malicious cyber actors using OAuth consent phishing in targeted attacks on prominent individuals, their family members, and personal acquaintances to gain persistent access to their accounts.

Similar to other forms of targeted phishing, the campaign involves impersonation of a trusted entity and tricks the victim into granting access to their account; however, this approach does not require the victim to disclose their username and password. The technique relies on OAuth, a commonly used authorization framework that allows websites and web applications to request access to a user’s account on another application, without exposing their login credentials.

With OAuth consent phishing, an attacker creates a malicious application and registers it with a legitimate OAuth provider. The application is configured with high-level privileges, such as the ability to access contacts, read and write emails, send emails on the user’s behalf, and more. The attacker then contacts the targeted individual via email or text and attempts to trick them into initiating the consent process.

In this campaign, the attackers typically impersonate publicly known personalities, government officials, journalists, and other high-profile individuals via a commercial messaging application (CMA). For instance, the individual is invited to take part in an event and must first verify their identity using the malicious but seemingly legitimate application.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

If the victim responds, they are presented with a legitimate permission request screen, such as for Microsoft 365, Google, or another legitimate cloud service. If the victim approves the request by clicking Allow, they provide their consent to the legitimate cloud service, which authorizes the malicious application to have the stated permissions through the provider’s authorization mechanism. The attacker is able to perform a range of malicious activities and access sensitive data without having to obtain the user’s password, and the technique bypasses multifactor authentication controls.

In practice, many users will not be aware that they have been successfully phished and will take no action. Should the victim smell a rat and change their password after granting access, the OAuth authentication token remains valid after the password change and will continue to provide the attacker with the previously granted permissions. The permissions must be revoked by removing the malicious app via the victim’s security settings.

The FBI advises users to be wary of this form of phishing and of any communications from unfamiliar phone numbers, accounts, or senders not in their contact list. Before taking any action in response to an unsolicited communication, users should first verify the identity of the sender and should only grant authorization to trusted applications. Even when the application is trusted, the requested permissions should be carefully assessed.

The post FBI Raises Alarm About OAuth Consent Phishing Activity appeared first on The HIPAA Journal.