ApolloMD Business Services, a business associate that provides integrated, multispecialty physician, APC, and practice management services, has agreed to settle a class action lawsuit stemming from a May 2025 ransomware attack. The attack was identified by ApolloMD on or around May 22, 2025, and the forensic investigation determined that a ransomware actor accessed its network between May 22 and May 23, 2025, potentially exfiltrating files containing the protected health information of patients of its healthcare provider clients.
The Qilin ransomware group claimed responsibility for the attack. The ApolloMD data breach included names, dates of birth, health information, health insurance information, and for some individuals, Social Security numbers, and was reported to the HHS’ Office for Civil Rights as affecting 626,540 individuals. The first batch of notification letters was mailed to the affected individuals starting in September 2025, with a second wave of notifications issued in March 2026.
The first class action lawsuits were filed shortly after the first round of notification letters were issued. In January 2026, the court granted the motion to consolidate the lawsuits into a single complaint – In re ApolloMD Data Breach Litigation – which was filed in the U. S.
District Court for the Northern District of Georgia, Atlanta Division. The consolidated lawsuit alleged that the ransomware attack occurred as a result of the failure of the defendant to implement reasonable and appropriate cybersecurity measures. ApolloMD denies all claims and contentions asserted in the action, including any wrongdoing and liability.
Following mediation in January 2026, the parties agreed on the material terms of a settlement, which has now been finalized and has received preliminary approval from the court. The defendant has agreed to establish a $4,020,000 settlement fund to pay benefits to the class members, after attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives have been deducted.
All class members are entitled to a one-year membership to a CyEx medical data monitoring service and may claim one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member. Alternatively, a pro rata cash payment may be claimed, estimated at $75 per claimant.
The cash payments will be subject to a pro rata increase or decrease depending on the number of claims received. The deadline for objection and opting out is August 31, 2026. Claims must be submitted by September 30, 2026, and the final fairness hearing has been scheduled for October 5, 2026.
The post ApolloMD Agrees to Pay $4. 02M to Settle Data Breach Lawsuit appeared first on The HIPAA Journal .
Originally published at hipaajournal.com