Veradigm and ApolloMD, both healthcare software and services vendors, reported data breaches to regulators after unauthorized actors accessed sensitive patient data through compromised customer credentials. Veradigm disclosed that the breach originated from a credential obtained from a customer, which was then used to access a Veradigm storage unit containing patient information. The incident, which occurred in December 2024 but was only recently discovered, highlights the ongoing risks associated with third-party vendor security in the healthcare sector. Both companies are notifying regulators and affected parties as required, and the breaches underscore the need for robust third-party risk management and timely breach notification.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
BankInfoSecurity and GovInfoSecurity reported that healthcare vendors Veradigm and ApolloMD disclosed health data hacking incidents. No additional details on the timing, scope, or sequence of the underlying breaches were provided in the reference content.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.