ApolloMD Agrees to $4.02 Million Settlement in Data Breach Lawsuit
ApolloMD Business Services has agreed to establish a $4.02 million settlement fund to resolve a class action lawsuit related to a May 2025 ransomware attack that affected the protected health information (PHI) of 626,540 individuals.
Settlement Receives Preliminary Court Approval
ApolloMD Business Services, a business associate offering various hospital practice management services, agreed to a settlement following litigation arising from a ransomware attack identified on or around May 22, 2025. The settlement has gotten preliminary approval from the U.S. District Court for the Northern District of Georgia, Atlanta Division.
After sending the initial breach notification letters, the first class action lawsuits were filed against ApolloMD. In January 2026, the court granted a motion to consolidate the lawsuits into a single action titled In re ApolloMD Data Breach Litigation. Following mediation conducted in January 2026, the parties agreed to the material terms of a settlement that has since been finalized and received preliminary court approval. Even so, ApolloMD denies the allegations of wrongdoing and liability.
Data Breach Details
A forensic investigation determined that a ransomware actor accessed the ApolloMD network between May 22 and May 23, 2025. The investigation found that files containing the PHI of patients of ApolloMD’s healthcare provider clients were potentially exfiltrated during the incident. The Qilin ransomware group claimed responsibility for the attack.
The reported data breach involved names, birth dates, health information, medical insurance information, and, for some individuals, Social Security numbers. ApolloMD reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights as impacting 626,540 individuals.
The first batch of notification letters was mailed beginning in September 2025. A second round of notifications was issued in March 2026.
Allegations in the Litigation
The consolidated complaint alleged that the ransomware attack resulted from ApolloMD’s failure to implement reasonable and appropriate cybersecurity measures. ApolloMD disputes those allegations and denies all claims asserted in the litigation.
Settlement Benefits
The settlement establishes a fund totaling $4,020,000. Settlement funds will be used to provide benefits to eligible class members after deductions for attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives. ApolloMD offered to eligible class members a one-year membership in a CyEx medical data monitoring service.
Class members may choose one of two cash payment options. Individuals may submit a claim for repayment of documented, unreimbursed expenses related to the data breach of up to $5,000 per class member. Alternatively, members may claim a pro rata cash payment that is estimated at $75 per claimant. The amount of the pro rata payment may increase or decrease depending on the number of valid claims submitted.
Important Settlement Dates
The last day to object to the settlement or opt out is August 31, 2026. Claims must be submitted by September 30, 2026. The final fairness hearing is scheduled for October 5, 2026.