Two servers that Modernizing Medicine was using to move records off retiring EHR platforms became a two-day doorway for an intruder in July 2025, and the Boca Raton vendor has now agreed to pay just under $3M to close the resulting class action.
The intruder reached those servers between July 9 and July 10, 2025, according to the vendor’s filing with the HHS Office of Civil Rights. Exposed records included names, addresses, dates of birth, phone numbers, email addresses, limited Social Security numbers, insurance details, and medical information. The filing put the tally at 198,795 people, and notifications went out around October 17, 2025.
Mediation on April 2, 2026 produced the material terms of the deal, and the court has since granted preliminary approval to a $2,999,750 fund. The complaint that started it, filed by Patricia Cavallaro-Kearins in the Southern District of Florida in late November 2025, accused the company of thin cybersecurity safeguards and raised claims for negligence, breach of implied contract, invasion of privacy, unjust enrichment, and breach of fiduciary duty. The company denies wrongdoing.
The pattern should worry health system CIOs. Legacy migration paths are often bolted on outside the main EHR environment, inherit weaker controls, and hold raw patient data in bulk. Retiring a platform is exactly when those shadow copies sit most exposed.