ApolloMD Confirms 626,500 Patients Affected by May 2025 Ransomware Attack
The extent of a May 2025 ransomware attack on the Georgia-based physician- and clinician-owned staffing and management group ApolloMD has recently been confirmed. The ransomware attack was detected on May 22, 2025; however, it has taken months for the investigation and data review to be completed. ApolloMD announced the attack in September 2025, when it started sending notification letters to the affected individuals’ physician practices, and on February 2, 2026, almost 9 months after the ransomware attack occurred, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) was informed that the incident involved unauthorized access to the electronic protected health information of 626,540 individuals. With more than 626,000 individuals affected, it was one of the most impactful healthcare ransomware attacks of the year, ranking above Covenant Health’s Qilin ransomware attack, which affected 478,188 patients. While severe, these attacks are small in comparison to the ransomware attack on Conduent Business Services, which is known to have affected...
Three Healthcare Providers Settle Class Action Data Breach Lawsuits
Settlements have received preliminary approval from the courts to resolve class action lawsuits against Northeast Rehabilitation Hospital Network, American Addiction Centers, and Midwest Physician Administrative Services (Duly Health and Care) over alleged impermissible disclosures of patients’ protected health information. Northeast Rehabilitation Hospital Network Data Breach Settlement Northeast Rehabilitation Hospital Network in New Hampshire has agreed to a settlement to resolve a class action data breach lawsuit stemming from a 2024 cyberattack by the Hunters International cyber threat group. The cyberattack was detected on or around May 22, 2024, and the lawsuit states that the private information of 148,515 individuals was compromised in the incident. The data breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 136,724 individuals. Data compromised in the incident included names, medical histories, treatment information, patient account numbers, billing/claims information, and health insurance information. Patients were...
Therapy Practice Management Software
Therapy practice management software is an administrative and clinical operations system used by behavioral health providers to manage scheduling, documentation, communications, telehealth, and billing while maintaining safeguards for protected health information under the HIPAA Privacy Rule and HIPAA Security Rule. Therapy practice management software supports end to end operational workflows for behavioral health services. Common functions include appointment scheduling, intake and consent handling, clinical documentation, patient communications, telehealth delivery, billing and payments, and reporting. When the software creates, receives, maintains, or transmits electronic protected health information, the vendor role and contract terms determine whether the vendor is a Business Associate and whether a Business Associate Agreement is required. HIPAA Compliance for Therapy Practice Management Software HIPAA compliance obligations apply when electronic protected health information is handled by a HIPAA Covered Entity or by a Business Associate performing functions or activities on...
83,000 Clients Affected by Cyberattack on Ohio Counseling Center
The Counseling Center of Wayne and Holmes Counties has experienced a cyberattack affecting 83,350 individuals. Data breaches have also been announced by Neurological Associates of Washington and Pecan Tree Dental. Counseling Center of Wayne and Holmes Counties The Counseling Center of Wayne and Holmes Counties (CCWHC) in Wooster, Ohio, has experienced a data security incident affecting 83,354 individuals. On March 3, 2025, CCWHC’s third-party service provider notified CCWHC about a cybersecurity incident, which caused disruption to its IT systems. An investigation was launched, and steps were taken to contain and remediate the incident. All impacted systems and accounts were removed, credentials were reset, and leading data privacy and security experts were engaged to assist with the investigation. The forensic investigation determined that an unauthorized third party gained access to a single CCWHC server on March 2, 2025, and exfiltrated files on March 3, 2025. Based on the initial findings of the investigation, the general types of information compromised in the incident include...
Staten Island University Hospital Settles Lawsuit Over Business Associate Data Breach
Staten Island University Hospital (SIUH) in New York has agreed to settle a class action lawsuit over a 2024 data breach involving one of its business associates. The data breach occurred in January 2024 at The Medibase Group Inc., a vendor that provides healthcare solutions, technical assistance, and business office solutions. On or around May 8, 2024, The Medibase Group notified SIUH that an unauthorized third party had gained access to Medibase systems, which contained the protected health information of 35,106 individuals. Data compromised in the incident included names, Social Security numbers, dates of birth, medical information, and health insurance information. Notification letters were mailed to the affected individuals on July 5, 2024. A class action lawsuit was filed by plaintiffs Belle De Santiago and Elena Girenko over the data breach – Santiago et al. v. Staten Island University Hospital – in the Superior Court of Cherokee County for the State of Georgia. The lawsuit alleged the data breach was the result of the defendant’s failure to implement reasonable...



