Thomas Davies, DPM Data Breach
Thomas Davies DPM: 14,581 Patient Records Exposed in EMR Hack
What happened in the Thomas Davies, DPM data breach?
The Thomas Davies, DPM data breach was reported on September 29, 2025 and affected 14,581 individuals. The breach type was Hacking/IT Incident involving Electronic Medical Record. This breach occurred in New York. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Thomas Davies, DPM Breach Details
Healthcare Data Breach Report: Thomas Davies, DPM
Incident Overview
On September 29, 2025, Thomas Davies, DPM, a podiatric medicine practice based in New York, reported a significant data breach affecting 14,581 individuals. The breach resulted from a hacking or IT incident that compromised the practice's Electronic Medical Record (EMR) system. This incident represents a substantial unauthorized access event affecting a notable patient population and triggering mandatory HIPAA breach notification requirements. The breach was discovered and reported within the required timeframe, indicating the practice's compliance with federal notification obligations.
Discovery and Response Timeline
While specific discovery details were not provided in the breach submission, the September 29, 2025 submission date indicates the practice identified the unauthorized access and initiated their breach response protocol. Upon discovery of the hacking incident, Thomas Davies, DPM likely conducted a forensic investigation to determine the scope of the breach, identify affected individuals, and assess what protected health information (PHI) may have been accessed. The practice would have been required to notify affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery of the breach, per HIPAA Breach Notification Rule requirements. Additionally, notification to the U.S. Department of Health and Human Services (HHS) and potentially media outlets would have been initiated, depending on the number of affected individuals and state requirements.
Technical Details of the Breach
Breach Vector and Method
The breach was classified as a "hacking/IT incident," which typically indicates unauthorized access to computer systems or networks through technical means rather than physical theft or loss of devices. Common hacking vectors in healthcare settings include credential compromise (stolen or weak passwords), exploitation of unpatched software vulnerabilities, phishing attacks targeting staff members, ransomware deployment, or direct network intrusion. The fact that the breach occurred within the EMR system—the centralized repository of patient medical records—suggests the attackers either gained direct access to the EMR platform or compromised network infrastructure providing access to it.
EMR systems are high-value targets for threat actors because they contain comprehensive patient information in a single location. A successful breach of an EMR typically provides access to multiple data categories simultaneously, including medical histories, diagnoses, treatment plans, and often demographic and insurance information. The scale of this breach (14,581 individuals) suggests either a sustained period of unauthorized access or a significant vulnerability that exposed a large patient database.
Organizational Context
Thomas Davies, DPM operates as a podiatric medicine practice in New York State. Podiatric practices typically serve patients for foot and ankle conditions, ranging from routine care to surgical interventions. As a healthcare provider maintaining patient medical records, the practice is a HIPAA-covered entity subject to federal privacy and security regulations. The practice's size, based on the number of affected patients, suggests either a single-location practice with a substantial patient base or potentially multiple locations serving the New York area. The use of an EMR system indicates the practice has invested in electronic health record infrastructure, which is standard for modern healthcare providers but also introduces cybersecurity responsibilities.
Impact Assessment
Number of Individuals Affected
The breach impacted 14,581 individuals, representing a significant patient population. This scale places the incident in the "high" severity category under standard breach assessment frameworks. For context, breaches affecting more than 10,000 individuals typically receive regional or national attention and trigger mandatory media notification in New York State. The affected individuals likely include current and former patients of the practice who had medical records stored in the compromised EMR system.
Personal Information Involved
Given that the breach occurred within an Electronic Medical Record system, the following categories of protected health information may have been exposed:
- Medical Information: Patient diagnoses, treatment histories, surgical records, medication lists, and clinical notes related to podiatric care
- Demographic Data: Names, dates of birth, addresses, and contact information
- Insurance Information: Health insurance policy numbers, group numbers, and insurance carrier details
- Identifiers: Medical record numbers, patient account numbers, and potentially Social Security numbers if used as identifiers
- Payment Information: Billing records, payment history, and potentially banking information for patients with payment plans
- Emergency Contact Information: Names and phone numbers of designated emergency contacts
The specific data elements exposed would depend on the EMR system's configuration and what fields were accessible to the attackers. Modern EMR systems typically contain comprehensive patient profiles, so it is reasonable to assume multiple data categories were compromised.
Risks to Affected Patients
Patients whose information was exposed in this breach face several potential risks:
Identity Theft and Fraud: With access to names, dates of birth, and potentially Social Security numbers, threat actors could attempt to open fraudulent accounts, apply for credit, or commit other forms of identity fraud. Medical identity theft—using someone's health insurance information to obtain medical services—is a particular concern in healthcare breaches.
Financial Fraud: Exposure of insurance information and banking details could enable unauthorized charges, fraudulent claims, or direct financial account compromise.
Medical Privacy Violations: Sensitive medical information, particularly regarding podiatric conditions or treatments, could be exposed to unauthorized parties, causing embarrassment or reputational harm to patients.
Phishing and Social Engineering: Threat actors may use exposed patient information to craft convincing phishing emails or social engineering attacks targeting patients or their family members.
Ransomware and Extortion: In some hacking incidents, threat actors may threaten to publicly release sensitive medical information unless a ransom is paid, creating additional distress for patients.
Recommended Actions for Patients
-
Monitor Credit Reports and Financial Accounts: Obtain free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) through AnnualCreditReport.com and review them for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
-
Review Medical Records and Billing Statements: Request a copy of your medical records from Thomas Davies, DPM to verify accuracy and check for any unauthorized services or treatments. Review all medical bills and insurance statements for suspicious charges or claims you did not authorize.
-
Enroll in Credit Monitoring and Identity Theft Protection: If offered by the practice, enroll in complimentary credit monitoring or identity theft protection services. These services can alert you to suspicious activity and provide recovery assistance if fraud occurs.
-
Change Passwords and Enable Multi-Factor Authentication: If you have an online patient portal account with the practice, change your password to a strong, unique credential and enable multi-factor authentication if available. Use different passwords for healthcare accounts and other online services.
-
Report Suspicious Activity Immediately: If you notice unauthorized charges, accounts, or medical services, contact your financial institutions, insurance company, and the practice immediately. File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you become a victim of identity theft.
HIPAA and Regulatory Context
This breach triggers obligations under the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414). Covered entities must notify affected individuals, the HHS Secretary, and potentially media outlets of breaches affecting more than 500 residents of a state or jurisdiction. New York State also has its own data breach notification law (General Business Law § 668) requiring notification of residents whose personal information has been compromised. The practice's September 29, 2025 submission date to the HHS Breach Notification Portal indicates compliance with federal reporting requirements.
Healthcare hacking incidents have increased significantly in recent years, with the HHS Office for Civil Rights reporting hundreds of breaches annually affecting millions of individuals. EMR system compromises represent a particularly concerning trend, as they provide attackers with comprehensive patient data in a single access point. This incident aligns with broader cybersecurity challenges facing healthcare providers, particularly smaller practices that may have limited IT security resources compared to large hospital systems.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Thomas Davies, DPM Breach
Monitor credit reports from all three major bureaus (Equifax, Experian, TransUnion) through AnnualCreditReport.com and consider placing a fraud alert or credit freeze to prevent unauthorized credit applications.
Review your medical records and billing statements from Thomas Davies, DPM for accuracy and unauthorized services; contact the practice and your insurance company immediately if you identify suspicious activity.
Enroll in any complimentary credit monitoring or identity theft protection services offered by the practice and set up fraud alerts with your financial institutions and insurance company.
Change your password for any online patient portal accounts with the practice to a strong, unique credential and enable multi-factor authentication if available; use different passwords for healthcare and other online accounts.
Report any unauthorized charges, accounts, or medical services to your financial institutions, insurance company, and the practice immediately; file a report with the Federal Trade Commission at IdentityTheft.gov if you become a victim of identity theft.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More New York Breaches
Search all breaches reported in New York
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits