HIPAA/HITECH
,
Litigation
,
Standards, Regulations & Compliance
Breach Affected More Than a Dozen Healthcare Clients, 2.5M Patients

Electronic health records vendor Veradigm – formerly AllScripts – agreed to a $10.5 million settlement ending consolidated class action litigation involving a December 2024 hacking incident that affected more than a dozen healthcare provider clients and about 2.5 million of their patients.
See Also: Demonstrating HIPAA Compliance
The litigation against Veradigm alleged negligence, breach of implied contract and unjust enrichment, among other claims.
Veradigm in a breach notice said it discovered on July 1, 2025, that some clients’ data had been accessed by an unauthorized actor exploiting a compromised credential to gain access to a Veradigm “storage unit” (see: Vendors Veradigm, ApolloMD Report Health Data Hacks).
“Although the incident occurred around Dec. 15, 2024, Veradigm only became aware of it recently through a third-party investigating the original data security incident involving the impacted customer,” Veradigm said at the time.
Data potentially compromised in the Veradigm breach varied among individuals but included name, date of birth, contact information, health information such as diagnoses and treatments, Social Security numbers, health insurance information, payment details and drivers’ license numbers.
Under the preliminary settlement, each class member is eligible to submit a claim for a cash payment of up to $5,000 for documented losses tied to the incident.
As an alternative, class members can instead choose to claim a pro rata payment of about $50. Each settlement class member also may submit a claim for two years of complimentary medical identity theft and fraud monitoring.
Plaintiffs’ attorneys are seeking one-third of the settlement fund, or about $3.5 million in fees and expenses.
Under the settlement, Veradigm agreed to provide to class counsel 14 days before the final court approval hearing – which is set for Feb. 18 – “a written and signed declaration” regarding the security enhancements the company implemented following the breach, or will implement in the future.
Veradigm will pay the costs of those additional security investments separate from the $10.5 million settlement fund.
More than a dozen Veradigm clients were affected by in the incident.
Those include: Virginia Ear, Nose and Throat Associates; Carolina Ear Nose and Throat Allergy Center; Neighborhood Health Center of Western New York; Cabarrus Eye Center; Family Medical Group of Texarkana; La Red Health Center; Urology Associates of Mobile; Peachtree Neurological Clinic; North Buncombe Family Medicine; Thomaston Medical Clinic; Henrietta Johnson Medical Center – Wilmington; Catholic Health Initiatives, including CommonSpirit Health and MercyOne; Nystrom and Associates; Genesis Healthcare, including Unio Specialty Care; Delaware Healthnet and Corona-Temecula Orthopedic Associates Medical Group.
