ModMed Data Breach Affects PII & PHI

Published
October 21, 2025
Updated
October 21, 2025
ModMed Data Breach Affects PII & PHI
Modernizing Medicine (ModMed)
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

Modernizing Medicine (ModMed)

data breach?

Join the Lawsuit

It's free to join. 

Modernizing Medicine, a company that provides electronic health records and other services to podiatry practices, experienced a data breach. On July 21, 2025, the organization detected suspicious activity within its computer servers.

On July 29, 2025, an investigation revealed that an unauthorized actor accessed and copied files containing sensitive information between July 9, 2025 and July 10, 2025. The cyber security incident compromised both personally identifiable information (PII) and protected health information (PHI). ModMed began notifying its impacted healthcare providers on Sept. 19, 2025.

According to notices mailed to affected individuals on Oct. 17, 2025, exposed information may have included full names, addresses, dates of birth, Social Security numbers, phone numbers, email addresses, health insurance information, medical record numbers, patient account numbers, dates of service, providers, practice names, billing and diagnostic codes, prescription and medication information and diagnosis and treatment information.

Modernizing Medicine also disclosed to the Massachusetts Attorney General on Oct. 17, 2025. Impacted patients includes at least 737 Massachusetts residents.

The cyberattack was also reported to the Vermont Attorney General's office on Oct. 20, 2025. The total number of affected individuals has not been released, but includes multiple practices and patients.

Modernizing Medicine's response

ModMed responded to the breach by blocking further unauthorized access, engaging cybersecurity experts and notifying law enforcement. In addition to required state and federal disclosures, the organization is offering individuals with compromised Social Security numbers free IDX credit monitoring and identity theft protection services.

If you receive notification from Modernizing Medicine or your provider about this breach, you may want to:

  • Sign up for the free credit monitoring and identity theft protection services, offered by ModMed.
  • Monitor your credit reports and financial accounts for any unusual activity.
  • Be alert for phishing emails or phone calls that may use your exposed information.
  • Consider placing a fraud alert or credit freeze with major credit bureaus.

More information about the healthcare services company can be found on the Modernizing Medicine website.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Consumers Notification date
Date of Breach
Breach Discovered Date
Total People Affected
Information Types Exposed
  • Full name
  • Address
  • Date of birth
  • Phone number
  • Email address
  • Health insurance information
  • Medical record number
  • Patient account number
  • Dates of service
  • Provider
  • Practice name
  • Billing/diagnostic codes
  • Prescription/medication information
  • Diagnosis and treatment information
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image