Breach taxonomy
Summary
Veradigm disclosed that one of its third-party vendors suffered a cybersecurity incident in which an unauthorized party obtained credentials from the vendor's environment for a Veradigm application programming interface used to serve customers. The attacker used those credentials to download patient personal data, including Social Security numbers in some cases, affecting a small number of Veradigm customers; no clinical or medical data was involved. Access was limited to that interface and did not reach Veradigm's broader network, servers or databases, and there were no operational disruptions. Affected customers and individuals are being notified with credit monitoring offered. Filed under Item 8.01; materiality not yet determined as of the filing date.
Tagging rationale
ThreatUnknown
Filing refers only to 'an unauthorized party' and does not identify an actor category -> UNKNOWN.
MethodsData ExfilAccount TakeoverSupply Chain
Filing states an unauthorized party 'obtained credentials from the vendor's environment' and 'used these credentials to download copies of certain personal data' -> DATA-EXFIL with ACCOUNT-TAKEOVER; the breach originated at a third-party vendor -> SUPPLY-CHAIN added.
AssetsPersonal Data
Filing states the unauthorized party downloaded 'certain personal data of patients, including, in some instances, Social Security numbers' -> PERSONAL-DATA.
EffectsInfo Privacy Loss
Filing discloses theft of patient personal data including SSNs while stating 'The incident did not result in any operational disruptions' -> INFO-PRIVACY-LOSS.
Business continuityNot Required
Filing states 'The incident did not result in any operational disruptions', so continuity procedures were not required -> Not Required.
Impact
Patient personal data including Social Security numbers was exfiltrated, but only for 'a small number of the Company's customers', through a limited API with no broader system access and no operational disruption -> score 2.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
Item 8.01 Other Events. Veradigm Inc. (the "Company") recently learned that one of its third-party vendors experienced a cybersecurity incident that impacted certain data associated with a small number of the Company's customers. Based on the Company's investigation to date, an unauthorized party obtained credentials from the vendor's environment to a Company application programming interface used by the vendor to provide services on behalf of the Company's customers. The unauthorized party used these credentials to download copies of certain personal data of patients, including, in some instances, Social Security numbers; no clinical or medical data was involved. The vendor's compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company's environment, including the Company's broader network, servers, databases, or other systems. The incident did not result in any operational disruptions. The Company promptly initiated its cybersecurity incident response protocols upon learning of the incident and has notified law enforcement. The Company's investigation is ongoing. The Company is reviewing the affected data, and affected customers and individuals are being notified, with credit monitoring services being offered where applicable. The Company has not yet determined the extent of any potential liabilities associated with this matter. However, based on the information currently available, the Company does not believe that this incident is reasonably likely to have a material impact on the Company's business, operations, financial condition, or results of operations.