John N. Evans, DPM Data Breach
Michigan Podiatry Practice Hit by Network Server Breach
What happened in the John N. Evans, DPM data breach?
The John N. Evans, DPM data breach was reported on June 3, 2023 and affected 15,512 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Michigan. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
John N. Evans, DPM Breach Details
Healthcare Data Breach Report: John N. Evans, DPM
Opening Summary
On June 3, 2023, John N. Evans, DPM, a podiatry practice based in Michigan, reported a significant data breach affecting 15,512 individuals. The breach resulted from unauthorized access to the practice's network server infrastructure, compromising patient protected health information (PHI) stored on networked systems. This incident represents a substantial security failure in the practice's IT infrastructure and has triggered mandatory HIPAA breach notification requirements under the Health Insurance Portability and Accountability Act.
Response and Investigation Timeline
The discovery and response timeline for this breach followed standard incident response protocols. Upon detection of unauthorized access to their network server, the practice initiated an investigation to determine the scope and nature of the compromise. The submission date of June 3, 2023, indicates that the practice completed its preliminary investigation and determined that notification to affected individuals was required under HIPAA regulations. The practice likely engaged IT forensics specialists to analyze the breach, determine what data was accessed, and identify the vulnerability that allowed unauthorized entry. Standard HIPAA requirements mandate that covered entities notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured PHI.
Specific Details of the Breach
Network server breaches typically occur through one or more common attack vectors. These may include exploitation of unpatched software vulnerabilities, weak authentication credentials, phishing attacks targeting staff members with network access, or misconfigured firewall rules that expose administrative interfaces to the internet. The fact that the breach location is identified as "Network Server" suggests that the attacker gained access to centralized data storage systems rather than individual workstations or portable devices. This type of breach typically allows threat actors to access large volumes of patient data simultaneously, which aligns with the significant number of individuals affected (15,512). Network server compromises often go undetected for extended periods, meaning the actual unauthorized access may have occurred weeks or months before discovery. The practice would have needed to determine the date of initial compromise, the duration of unauthorized access, and what specific data repositories were accessed during the intrusion.
Organizational Context
John N. Evans, DPM operates as a podiatry practice in Michigan, providing foot and ankle care services to patients throughout the state. As a solo or small group practice, the organization likely maintains patient records electronically through a practice management system and electronic health record (EHR) platform. Podiatry practices typically serve a local to regional patient population and maintain comprehensive patient files including medical histories, treatment records, and billing information. The practice's IT infrastructure, like many small to mid-sized healthcare providers, may have had limited dedicated IT security resources, which could contribute to vulnerabilities in network security posture. Small healthcare practices often struggle with implementing enterprise-grade security controls while managing operational costs, creating a gap between security best practices and actual implementation.
Patient Impact and Notification
Approximately 15,512 patients of John N. Evans, DPM had their protected health information potentially compromised in this breach. This substantial patient population suggests the practice has been operating for a considerable time and serves a significant geographic area within Michigan. The affected individuals likely include current and former patients whose records were stored on the compromised network server. These patients would have received breach notification letters detailing what information was exposed, the date range of potential unauthorized access, and recommended steps to protect themselves. Under HIPAA requirements, the practice was obligated to provide specific information in these notifications, including a description of the breach, the types of information involved, steps patients should take to protect themselves, what the practice is doing to investigate and prevent future breaches, and contact information for questions.
Data Exposure and Risk Assessment
Personal Information Involved
Network server breaches at healthcare practices typically expose multiple categories of sensitive patient information. Based on the nature of podiatry practice operations, the compromised data likely includes:
- Full names and contact information (addresses, phone numbers, email addresses)
- Social Security numbers (commonly used as patient identifiers in healthcare)
- Date of birth and demographic information
- Medical history and clinical notes related to foot and ankle conditions
- Diagnosis and treatment information
- Prescription records
- Insurance information including policy numbers and group numbers
- Billing and payment information
- Emergency contact information
- Potentially financial account information used for payment processing
The combination of these data elements creates significant risk for identity theft and medical fraud, as attackers would have sufficient information to impersonate patients or access their financial accounts.
Industry Context and HIPAA Implications
Network server breaches represent one of the most common categories of healthcare data breaches, accounting for a substantial percentage of reported incidents annually. According to HHS breach notification data, hacking and IT incidents consistently rank among the top breach types affecting healthcare providers. The exposure of 15,512 individuals places this incident in the regional significance category, as it affects a meaningful portion of a state's healthcare population. HIPAA requires that covered entities implement appropriate administrative, physical, and technical safeguards to protect electronic PHI, including access controls, encryption, audit controls, and integrity controls. This breach suggests that one or more of these required safeguards may have been inadequate or improperly implemented. The fact that no business associate was involved indicates that the breach occurred within the practice's own systems rather than through a third-party vendor, placing full responsibility on the practice for the security failure. Similar breaches at small healthcare practices have resulted in significant financial penalties, reputational damage, and loss of patient trust.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the John N. Evans, DPM Breach
Place a fraud alert with the three major credit bureaus (Equifax, Experian, TransUnion) and consider placing a credit freeze to prevent unauthorized account opening in your name
Monitor your credit reports regularly for suspicious activity and review your credit card and bank statements monthly for unauthorized charges or transactions
Contact your insurance company to verify that no fraudulent claims have been filed using your policy information and request new policy numbers if available
Consider enrolling in credit monitoring and identity theft protection services, which the practice may offer at no cost as part of their breach response; watch for notification letters containing details about available resources
Review your medical records with your healthcare providers to ensure no unauthorized treatment or prescriptions have been added to your account
Be cautious of unsolicited communications requesting personal or medical information, as attackers may use phishing or social engineering tactics targeting breach victims
Document all breach-related communications and keep records of any fraudulent activity discovered, as this documentation may be needed for dispute resolution or legal claims
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Michigan Breaches
Search all breaches reported in Michigan
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits