3rd Party Risk Management
,
Data Privacy
,
Data Security
Settlement With Revenue Cycle Vendor Stems From Qilin Gang Attack Affecting 627,000

Revenue cycle management services firm ApolloMD Business Services has agreed to pay just over $4 million to settle proposed class action litigation stemming from a May 2025 data theft incident. Ransomware gang Qilin claimed responsibility for the hack, which affected nearly a dozen physician practices and 627,000 of their patients.
See Also: The End of Plausible Deniability: Data Privacy Compliance in 2026
Under the proposed settlement, for which a final court hearing is set for Oct. 5, Atlanta-based ApolloMD will pay cash payments of up to $5,000 for each claim of reasonable documented losses from fraud or identity theft related to the breach, or an alternative pro rata cash payment of $75 for claims not requiring any loss documentation.
Settlement class members are also eligible for one year of medical data monitoring.
Among other claims, the consolidated class action lawsuit filed in a Georgia federal court in February alleged that ApolloMD was negligent by failing to safeguard the plaintiffs’ and class members’ sensitive information against cybercriminals.
The Qilin ransomware group last year claimed to have exfiltrated 238 gigabytes of ApolloMD data (see: Vendors Veradigm and ApolloMD Report Health Data Hacks).
Under the settlement, ApolloMD denies the legal claims and contends it didn’t violate any laws in the incident.
ApolloMD in its breach notice to affected individuals said it first became aware of the cyber incident on May 22, 2025, after it detected unusual activity in its IT environment. The investigation determined that an unauthorized party accessed the vendor’s IT systems between May 22 and May 23, 2025, acquiring files containing information for patients treated by ApolloMD’s affiliated physicians and practices.
The potentially compromised information varied among the victims, but included names, dates of birth, addresses, diagnosis information, provider names, dates of service, treatment information and health insurance information. For some individuals, Social Security numbers were also compromised.
ApolloMD reported the hack to federal regulators in February as a business associate, saying the incident affected the protected health information of 626,540 people. The company sent two waves of notifications to affected individuals – the first beginning in September 2025 and the second in March 2026.
Under the settlement, plaintiff and class member lawyers have requested $1.34 million in attorneys’ fees, plus reimbursement of costs, which will be deducted from the $4.02 settlement fund .
ApolloMD, which provides an array of multispecialty practice management services to hospitals and doctors, is among a long and growing list of large revenue cycle management, medical billing, electronic health record and related third-party vendors that have been the center of major health data breaches in recent years (see: AI Threats Put Healthcare Vendors in Hackers’ Crosshairs).
Among them was Trizetto Provider Solutions, a unit of Cognizant, which in February reported to federal regulators a 2024 hack affecting 3.4 million individuals.
Also, electronic health records vendor Veradigm, formerly Allscripts, reported last September a breach affecting nearly 2.7 million people. In January, Veradigm agreed to pay $10.5 million to settle class action litigation stemming from that incident (see: EHR Vendor Veradigm to Pay $10.5M to Settle Hack Lawsuit).
