---
title: "Ten Weeks After the Money Arrived, Two Retiring Servers Got Popped"
description: "On April 30, 2025, Clearlake Capital finalized a majority investment in Modernizing Medicine (\"ModMed\"), valuing the specialty healthcare software-as-a-service (SaaS) company at $5.3 billion. Ten weeks later, on July 9, an unauthorized party accessed two servers inside ModMed's infrastructure. These"
url: https://kaynemcgladrey.com/blog/ten-weeks-after-the-money-arrived-two-retiring-servers-got-popped/
date: 2026-09-25
modified: 2026-09-25
author: "Kayne"
image: https://kaynemcgladrey.com/wp-content/uploads/2026/09/Ledger.webp
categories: ["Blog"]
type: post
lang: en-US
---

# Ten Weeks After the Money Arrived, Two Retiring Servers Got Popped

On April 30, 2025, Clearlake Capital [finalized a majority investment](https://clearlake.com/news/modmed-a-leading-healthcare-saas-platform-announces-significant-majority-growth-investment-from-clearlake-capital/) in Modernizing Medicine (“ModMed”), valuing the specialty healthcare software-as-a-service (SaaS) company at $5.3 billion. Ten weeks later, on July 9, an unauthorized party accessed two servers inside ModMed’s infrastructure. These weren’t production systems powering the electronic health records (EHR) used by 40,000 providers. They were legacy boxes holding data migrating off retiring platforms, waiting to be decommissioned, and still full of protected health information (PHI) when someone walked in the door.

> “The exposure of one’s PII/PHI to cybercriminals is a bell that cannot be unrung.”
> — Class Action Complaint, Cavallaro-Kearins v. Modernizing Medicine, para 7

## How the Incident Unfolded

ModMed detected suspicious activity on those two servers on July 21, 2025, but patients didn’t hear about it until October 17. That stretch, 88 days of post-detection silence and a full 100 days from the breach itself, became a central allegation in the litigation, with plaintiffs arguing the delay stripped class members of any chance to mitigate their personal risks ([Complaint, paras 18-24](https://storage.courtlistener.com/recap/gov.uscourts.flsd.701595/gov.uscourts.flsd.701595.1.0.pdf)).

According to the [Motion for Preliminary Approval](https://storage.courtlistener.com/recap/gov.uscourts.flsd.701595/gov.uscourts.flsd.701595.16.0.pdf), the affected population came to 386,423 people. The [exposed records](https://www.cyber.nj.gov/Home/Components/News/News/1843/216) included Social Security numbers, health insurance details, diagnoses, and prescription information. And the data didn’t just get viewed; someone listed a [partial database for sale](https://databreaches.net/2025/10/24/modmed-revealed-they-were-victims-of-a-cyberattack-in-july-then-some-data-showed-up-for-sale/) on a cybercrime forum that October, complete with verifiable patient records from Indiana and South Carolina. The exfiltration was real, not theoretical.

The legal machinery, meanwhile, [moved at a pace](https://www.courtlistener.com/docket/71934808/cavallaro-kearins-v-modernizing-medicine-inc/) most breach defendants would envy:

- **July 9, 2025**: Unauthorized access to the two migration servers begins
- **July 21, 2025**: Suspicious activity detected
- **September 19, 2025**: Provider notifications begin
- **October 17, 2025**: Patient notifications begin
- **November 19, 2025**: Class action filed, just over a month after notices went out
- **April 2, 2026**: Full-day JAMS mediation in Miami with Bruce Friedman
- **May 26, 2026**: Settlement papers filed; no answer, no motion to dismiss, ever
- **June 29, 2026**: Preliminary approval granted after a 10-minute hearing
- **November 2, 2026**: Claims filing deadline
- **November 17, 2026**: Final approval hearing scheduled

## What the Incident Cost

Executives need the balance sheet, not the press release. The [initial documented cost](https://storage.courtlistener.com/recap/gov.uscourts.flsd.701595/gov.uscourts.flsd.701595.16.1.pdf) is a $2,999,750 non-reversionary settlement fund, all cash, paid by the company. Inside that fund, plaintiffs’ counsel will request up to one-third for fees (roughly $1 million) plus costs, and administering a 386,000-person notice program will likely eat several hundred thousand more. Whatever remains gets divided among class members who file claims, with an [estimated $75 alternate payment](https://modernizingmedicinedatasettlement.com/faq) for those lacking documented losses. Note the word “estimated,” because the pro rata mechanism means that figure moves with claim volume.

Beyond the fund, some estimates help fill in where public records stop:

| Component | Low | High |
| --- | --- | --- |
| Settlement Fund (documented) | $2,999,750 | $2,999,750 |
| Defense counsel (estimated) | $390,000 | $1,135,000 |
| Breach response (estimated) | $435,000 | $1,145,000 |
| **Total** | **$3,824,750** | **$5,279,750** |

Legal costs are comparably low, because ModMed never answered the complaint, never filed a motion to dismiss, and participated in exactly one mediation day. Alston & Bird’s engagement therefore spans incident response counseling from July onward, informal discovery, the settlement negotiation, and the approval process. A case this short doesn’t support a big ticket legal invoice, but it also wasn’t free.

The breach response estimate covers the typical costs for forensics on the two servers, printing and mailing notification letters to 386,423 people at roughly $1 apiece, call center staffing, and the credit monitoring ModMed offered alongside its letters (a product the settlement FAQ references when barring double recovery).

Churned customers, reputational drag, and any regulatory exposure aren’t in these figures, and they all push the total upward. Spread across the affected population, the company spent roughly $10 to $14 per person just managing the aftermath of two forgotten servers.

## What Prevention Would Have Cost

What could it have cost to secure hardware with a known retirement date, holding known data types?

A reasonable approach would be:

- Asset inventory and data mapping to identify what lived on legacy platforms ($50,000-150,000, one-time)
- Encryption at rest and network segmentation for those servers ($100,000-300,000, one-time)
- Secure decommissioning once migration completed ($50,000-100,000, one-time; considerably cheaper if you have an industrial shredder handy)
- Dedicated monitoring of transitional infrastructure until retirement ($50,000-100,000 per year)

The three one-time items sum to $200,000 at the floor and $550,000 at the ceiling, so call it $375,000 upfront at the midpoint, plus modest monitoring until the servers were retired. Fold in that first year of monitoring and the total first-year outlay spans $250,000 to $650,000.

Nobody at ModMed sat down and decided to skip encryption on two dying servers. That’s the entire problem. Unconscious risk acceptance is still risk acceptance, and this one priced out badly. Run the full first-year prevention range against the total incident cost and the multiple lands between 5.9 times ($3.82 million in costs against $650,000 spent preventing it) and 21.1 times ($5.28 million against $250,000). At the midpoints of both figures, the incident cost about 10 times the prevention bill – almost exactly the order of magnitude the individual components imply.

## Reading It as Business Risk

ModMed’s private, so its financials aren’t available as audited public records. Third-party aggregators (Prospeo, RocketReach, Growjo) put revenue between $275 million and $334 million, and profit has to be modeled at assumed EBITDA margins. Each scenario below assumes the revenue and margin stated in the row, holds prevention at the $375,000 one-time midpoint (the recurring monitoring is excluded here because this table measures the capital decision, not the annual run-rate), and uses the cost bound matched to that row (low cost in the conservative row, midpoint cost centrally, high cost in the optimistic row).

| Scenario | Revenue / Margin | Annual Profit | Incident Cost | Prevention Cost |
| --- | --- | --- | --- | --- |
| Conservative | $275M, 10% | $27.5M | 13.9% | 1.4% |
| Central | $300M, 15% | $45.0M | 10.1% | 0.8% |
| Optimistic | $334M, 20% | $66.8M | 7.9% | 0.6% |

Here’s the thing, though: the pattern holds no matter which scenario you pick. Even the most optimistic scenario costs nearly 8 percent of a year’s earnings for the incident, while the fix that probably prevents it never exceeds 1.5 percent of a year’s profit in even the most conservative scenario. Analysts model risk as probabilities and insurance premiums. This case shows risk as a line item that materialized after the fact, at multiples of what it would have cost to erase from the books in advance.

## Chronology Isn’t Causation

The Clearlake deal closed April 30, 2025, and the breach began July 9, 2025. Ownership transitions routinely loosen asset discipline, and legacy infrastructure is where things fall through cracks during handoffs. The sequence fits a pattern every consultant in this field has seen; however, there’s no way to say for sure thats what happened. What the record does show is that servers earmarked for retirement held live PHI and weren’t hardened or retired in time.

## What’s Left

Claims must be filed by November 2, 2026, with final approval riding on the November 17 fairness hearing and any appeals that follow. The fee award hasn’t been set, and the actual claim rate, which determines what each class member will receive, is unknown until the process finishes. ModMed admitted no liability in the agreement, which is typical.

Every number in this piece was a decision someone could have made differently, at a known price, before July 9, 2025. The breach wasn’t an AI superpower or an APT group with a zero day. It was two old servers, a known migration project, and a missing line item. The ~$4.6 million in costs could have been easily prevented with a fraction of that sum.
