[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fw3j25sb8o4aj":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":40,"seoTitle":41,"seoTitleEn":42,"seoDescription":41,"seoDescriptionEn":43,"logoUrl":44,"isVerified":4,"isSensitive":4,"isSpamList":45,"isMalware":45,"company":46},"6a70b7ff35cc8b949460ff06","ModernizingMedicine2025","ModMed 2025 Data Breach","modmed-2025","modmed.com","2025-07-09T00:00:00.000Z","2026-08-03T15:47:10.909Z","HHS OCR and independent healthcare-security reporting","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf",[14,16],"https:\u002F\u002Fwww.hipaajournal.com\u002Fdata-breache-modmed-lifebridge-health-right-at-home\u002F",198795,"known",null,"people","High",[23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39],"Names","Dates of birth","Physical addresses","Phone numbers","Email addresses","Social security numbers","Driver's license numbers","Government issued IDs","Medical record numbers","Patient account numbers","Healthcare provider information","Billing information","Diagnoses","Prescription information","Treatment information","Health insurance information","Financial account information","\u003Cp>\u003Cstrong>The 2025 ModMed data breach\u003C\u002Fstrong> involved unauthorized access to Modernizing Medicine's servers on July 9 and 10, 2025, and the copying of certain files. The U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR) reports that the incident affected 198,795 people.\u003C\u002Fp>\u003Cp>Modernizing Medicine is the corporate name behind ModMed, a provider of electronic health record and practice-management software to healthcare organizations. This record covers the server incident the company confirmed in July 2025.\u003C\u002Fp>\u003Ch2>How did the ModMed data breach happen?\u003C\u002Fh2>\u003Cp>ModMed detected suspicious activity on its servers on July 21, 2025. Its investigation confirmed that unauthorized access occurred on July 9 and 10 and that files containing sensitive information were copied.\u003C\u002Fp>\u003Cp>The company's public disclosures do not identify the initial-access method, an exploited software vulnerability, or the responsible actor. The incident is therefore not attributed to an unconfirmed attack technique or threat actor.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>The categories varied by person. Disclosed fields may have included names, dates of birth, addresses, phone numbers, email addresses, Social Security numbers, driver's-license numbers, or other government-issued identification numbers.\u003C\u002Fp>\u003Cp>Medical record and patient account numbers, provider and practice names, billing and diagnostic codes, prescription or medication information, diagnosis and treatment details, and health-insurance information may also have been involved for some people. Bank or financial-account information was also within the disclosed scope. ModMed said full medical records were not involved.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The HHS OCR record reports 198,795 affected individuals for the network-server Hacking\u002FIT Incident. This is the event's affected-person total; it does not mean every listed data category was exposed for every person.\u003C\u002Fp>\u003Ch2>What risks can this information create?\u003C\u002Fh2>\u003Cp>Identity fields such as Social Security numbers, dates of birth, and addresses can increase the risk of identity theft, fraudulent account applications, or tax fraud when combined. Financial-account and government-ID information can also be used in fraud attempts.\u003C\u002Fp>\u003Cp>Medical, prescription, insurance, and provider details can help an attacker create targeted messages that appear to refer to a real treatment relationship. Accurate-looking health details do not prove that the sender is authorized.\u003C\u002Fp>\u003Ch2>How did ModMed respond?\u003C\u002Fh2>\u003Cp>ModMed opened an investigation, reviewed the affected files, and notified relevant healthcare providers on September 19, 2025. Mailing of individual notification letters began on October 17, 2025.\u003C\u002Fp>\u003Cp>People whose Social Security numbers were involved were offered complimentary credit monitoring and identity-theft protection. The company also said it took additional security steps intended to prevent similar incidents.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients can monitor credit reports, bank accounts, health-insurance statements, and medical bills for unfamiliar activity. If a Social Security number was involved, a credit freeze or fraud alert may be appropriate.\u003C\u002Fp>\u003Cp>For an unexpected message claiming to come from ModMed, a medical practice, or an insurer, use the organization's official contact channel before following a link. Do not share a password, payment detail, or verification code.\u003C\u002Fp>","","ModMed Data Breach (198.8 Thousand People Affected)","The ModMed data breach affected 198,795 people and may have exposed identity, financial, insurance, and medical information.","\u002Fuploads\u002Flogo\u002Fmodmed-official.png",false,{"name":47,"sector":48,"country":49,"website":50,"websiteArchiveUrl":41,"websiteStatus":41,"websiteCheckedAt":19},"Modernizing Medicine (ModMed)","Healthcare","United States","https:\u002F\u002Fwww.modmed.com\u002F"]