25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

ApolloMD Agrees to Pay $4.02M to Settle Data Breach Lawsuit

ApolloMD Business Services, a business associate that provides integrated, multispecialty physician, APC, and practice management services, has agreed to settle a class action lawsuit stemming from a May 2025 ransomware attack.

The attack was identified by ApolloMD on or around May 22, 2025, and the forensic investigation determined that a ransomware actor accessed its network between May 22 and May 23, 2025, potentially exfiltrating files containing the protected health information of patients of its healthcare provider clients. The Qilin ransomware group claimed responsibility for the attack.

The ApolloMD data breach included names, dates of birth, health information, health insurance information, and for some individuals, Social Security numbers, and was reported to the HHS’ Office for Civil Rights as affecting 626,540 individuals. The first batch of notification letters was mailed to the affected individuals starting in September 2025, with a second wave of notifications issued in March 2026.

The first class action lawsuits were filed shortly after the first round of notification letters were issued. In January 2026, the court granted the motion to consolidate the lawsuits into a single complaint – In re ApolloMD Data Breach Litigation – which was filed in the U.S. District Court for the Northern District of Georgia, Atlanta Division.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The consolidated lawsuit alleged that the ransomware attack occurred as a result of the failure of the defendant to implement reasonable and appropriate cybersecurity measures. ApolloMD denies all claims and contentions asserted in the action, including any wrongdoing and liability. Following mediation in January 2026, the parties agreed on the material terms of a settlement, which has now been finalized and has received preliminary approval from the court.

The defendant has agreed to establish a $4,020,000 settlement fund to pay benefits to the class members, after attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives have been deducted. All class members are entitled to a one-year membership to a CyEx medical data monitoring service and may claim one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member. Alternatively, a pro rata cash payment may be claimed, estimated at $75 per claimant. The cash payments will be subject to a pro rata increase or decrease depending on the number of claims received.

The deadline for objection and opting out is August 31, 2026. Claims must be submitted by September 30, 2026, and the final fairness hearing has been scheduled for October 5, 2026.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist