The Boca Raton-based organization has agreed to pay $3 million to settle a class action lawsuit.

 

What happened

Modernizing Medicine has agreed to a settlement regarding a data breach that took place in 2025 as the software company worked to convert data from an older electronic health record system to a newer one.

The class action suit, Cavallaro-Kearins v. Modernizing Medicine, Inc., was filed on November 19th, 2025 in the U.S. District Court for the Southern District of Florida. Overall, the lawsuit alleged that the breach was a product of insufficient cybersecurity measures, but the lawsuit also made claims of negligence, breach of implied contract, invasion of privacy, and more.

Both parties agreed to mediation and determined the terms of the settlement on April 2nd, 2026. Modernizing Medicine agreed to establish a settlement fund of $2,999,750 that will go towards costs associated with the settlement and benefits for class action members. Under the terms of the agreement, Modernizing Medicine has denied any claims of wrongdoing.

 

The backstory

Modernizing Medicine is a technology company that provides cloud-based AI-powered software and electronic health record systems for health providers. They work with practices to store data and help authorized users access it when needed. Given that the company’s focus is on storing data, they hold a trove of critical documentation.

According to the data breach notice reported to the Massachusetts Attorney General, the breach occurred in July 2025, when a hacker accessed two of the company’s computer servers over two days. Data compromised included names, addresses, dates of birth, phone numbers, email addresses, limited Social Security numbers, health insurance information, and medical information. A total of 198,795 individuals were impacted and informed beginning September 19th, 2025.

 

In the know

Modernizing Medicine has faced other legal troubles and subsequent financial hits in previous years. Back in 2017, Modernizing Medicine faced a lawsuit under the False Claims Act, which alleged that the organization falsely claimed to have software that met government-required certification criteria. Specifically, the lawsuit claimed that there were flaws in ModMed’s system that made it unreliable.

The suit also alleged that the company was paying kickbacks to doctors, an illegal practice of paying individuals for referrals to Modernizing Medicine. In 2022, the suit was resolved through a settlement, with Modernizing Medicine ultimately agreeing to pay $45 million. Other healthcare companies that were part of the scheme, like Miraca, also made settlement agreements in separate lawsuits.

 

The big picture

While the two lawsuits may not initially seem connected, they point to potential issues with Modernizing Medicine’s EHR system. The 2022 lawsuit claimed that the system itself had many flaws that made it unreliable for secure use by the government, while the 2025 data breach stemmed from accessing computer servers as data migrated from an older system. The 2025 incident shows that Modernizing Medicine is working to improve their systems by retiring old systems, but switching to new tools requires risk analysis and a safe migration process.

For the company, two settlements within five years could spell financial trouble for years to come. Even after a data breach is resolved, there can be unforeseen costs associated with security and prevention. A Paubox article notes that organizations also often deal with loss of client trust, operational delays, and administrative costs like providing notifications.

 

FAQs

Do some data breaches result in higher settlements than others?

Yes, settlements are largely determined by the number of people who were impacted, the type of data involved, and other factors, life if the breach was preventable. In this case, the breach may seem relatively larger than others because of the nature of the data, like Social Security numbers, which carry a higher risk of theft.

 

Will hospitals and doctors still use Modernizing Medicine?

Yes. According to the company’s website, they still help 160,000 healthcare professionals. It’s possible that some of these organizations and individuals may switch EHR providers due to lack of trust or better options, just because the company faced one data breach, it doesn’t necessarily mean their system isn’t good or shouldn’t be used. If Modernizing Medicine works to improve their security, it’s very possible that the company can thrive.