Electronic health record company says customer data stolen in breach | The Record from Recorded Future News

https://therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach

36 points · 5 comments · view on lemmy.world

5 Comments

schipelblorp@sh.itjust.works · 15 pts · 5d (1 reply)

Veradigm provides health record technology and management systems to thousands of hospitals and doctors across the world, reporting $594 million in revenue in 2024.

This is a real fucking problem. There are so many third-parties involved with managing PHI data, it's impossible to secure it. And no doubt people are trying to grab live audio of doctors visits to train AI, too.

FineCoatMummy@sh.itjust.works · 4 pts · 5d

so many third-parties involved with managing PHI, it’s impossible to secure it.

For sure! I got notified my PHI was breached. By a company I never even heard of! And certainly never directly used. I never even figured out the chain, from health services I used, to the breached co. Might have been multiple others between. Given how often these breaches happen, defacto we have no medical privacy.

And no doubt people are trying to grab live audio of doctors visits

Happens already, yah! New England Journal of Medicine has a paper about the privacy risks. Prob lots of other papers too, that's just what I had in my bookmark list.

These systems capture audio of clinical encounters and generate transcripts and structured clinical notes, yet vendor practices differ substantially in how long each data type is retained and whether it is used for AI training.

Offices are supposed to have signs, and/or the dr should tell the pt. But drs are human, right? They may forget! And sometimes, you may be there in your worst, vulnerable moments. When you are badly injured, or distressed.

It chantges the whole trust relationship between dr & pt.

pageflight@piefed.social · 6 pts · 5d (1 reply)

I thought this was a duplicate, but no, same company lost data due to stolen credentials in 2024.

a data security incident at one of its customers resulted in credential theft that allowed access to a Veradigm storage account

Cyber@feddit.uk · 5 pts · 5d

They just don't want to protect themselves:

Veradigm provides health record technology and management systems to thousands of hospitals and doctors across the world, reporting $594 million in revenue in 2024. [...] Formerly known as Allscripts, Veradigm has experienced cybersecurity incidents in the past. It was attacked by the SamSam ransomware gang in 2019 and faced several class action lawsuits due to the incident, which caused outages across thousands of hospitals. The company also reported a different cybersecurity incident in December 2025, telling the U.S. Department of Health and Human Services that 2,672,036 people had health data exposed during a breach in December 2024.

$594M and they get hit 3 times (that we know of).

Why not hire a security consultant for a few months...

lemmysmash@piefed.social · 2 pts · 5d

Roses are red.

Violets are kitsch.

Electronic health record company says customer data stolen in breach