Modernizing Medicine Inc. Informational Website

Brand Protection Software
Notice of Data Breach
10/17/2025

Modernizing Medicine, Inc. (“ModMed”), which provides electronic health record (EHR) and other services to podiatry providers, is providing notice of an incident that may have involved limited personal information for patients and other individuals associated with certain of its podiatry providers who used the EHR systems known as Sammy and TRAKnet. The incident did not involve access to customer instances of ModMed’s flagship EHR products, EMA or gGastro, did not involve full medical records, and did not disrupt clinical operations or live production systems in any way.

 

ModMed notified affected podiatry provider customers beginning on September 19, 2025. Notices to affected individuals are being mailed by ModMed in coordination with, and per instructions by, affected customers who do not opt out of ModMed’s notification process and for whom ModMed has a sufficient address. Not all ModMed podiatry customers were affected.

 

Because ModMed may not have sufficient addresses for everyone, ModMed is providing this substitute notice link, consistent with the Health Insurance Portability and Accountability Act (HIPAA). Each affected customer of ModMed will determine, consistent with HIPAA, whether to post the link for a substitute notice on their own website. This substitute notice link provided by ModMed will remain active for at least 90 days.

 

NOTICE OF DATA BREACH

 

 

What happened?

On July 21, 2025, ModMed became aware of potential unauthorized activity in certain computer servers, which ModMed subsequently determined involved servers containing limited data from some of our podiatry customers. We immediately took steps to prevent any further unauthorized activity and began an investigation, including engaging a leading forensic firm. We also contacted law enforcement. Based on our review, we learned on July 29, 2025, that an unauthorized third party was able to see and take copies of some information in the podiatry computer servers between July 9, 2025, and July 10, 2025. We conducted a comprehensive data review of the impacted information to identify the affected practices and patients, and we notified the affected customers beginning September 19, 2025.

 

What information may have been involved?

Based on the review, individuals’ personal information involved in this incident may have included one or more of the following: full name, address, date of birth, phone number, email address, health insurance information, and medical information (such as medical record number, patient account number, date(s) of service, provider and practice name, billing/diagnostic codes, prescription/medication information, and/or diagnosis and treatment information). Some of this information may also have been related to a parent, guardian, or subscriber. For some individuals, a Social Security number may have also been involved. Bank/financial account information, credit card information, driver’s license number, government ID card, and full medical records were not involved in this incident. Please note that not all data elements were involved for all individuals.

 

What we are doing

ModMed takes privacy and security very seriously. In response to this incident, we immediately took action to block and prevent further unauthorized activity. We have further enhanced our security controls and practices as appropriate to minimize the risk of a similar incident in the future.

 

What you can do

We are not aware of any misuse of individuals’ information as a result of this incident to date. The below Reference Guide includes information on general steps that affected individuals can take to monitor and help protect their personal information. Please review this Reference Guide in the Additional Resources tab below. We also encourage individuals to carefully review statements sent from health care providers and insurance companies to ensure that all account activity is valid. Any questionable charges should be promptly reported to the appropriate provider or company with which you maintain the account, such as your bank.

 

For more information:

If you have any questions or concerns, please call us toll-free at 1-833-353-4513. This call center is open from 9 am – 9 pm Eastern Time, Monday through Friday, except holidays. You can also view the FAQs below for more information. We are sorry for any concern this incident may cause.

Learn More