The business associate has agreed to settle a lawsuit stemming from a ransomware attack that took place last year.

 

What happened

ApolloMD Business Services, an Atlanta-based medical management firm, recently agreed to settle a class action suit that resulted from a large breach that occurred in May of 2025.

Although four class action suits were independently filed, they were all consolidated into a single complaint: In re ApolloMD Data Breach Litigation, which was filed in the U.S. District Court for the Northern District of Georgia.

As is common in data breach settlements, the settlement allows Apollo to deny any claims of wrongdoing, but they have still agreed to pay $4.02 million, which go towards class members, service awards, attorney fees, and other administrative costs.

The final fairness hearing, which is the judge’s final evaluation of the terms of the settlement, is scheduled for October 5th, 2026, and is expected to be completed without issue.

 

Going deeper

According to the settlement agreement, ApolloMD became aware of suspicious activity on May 22nd, 2025. The company soon determined that its IT network had been breached between May 22nd and May 23rd, resulting in files being accessed and/or acquired. The ransomware attack impacted approximately 626,540 individuals, involving information like names, dates of birth, health information, health insurance information, and for some individuals, Social Security numbers.

The settlement agreement also stated that the first batch of breach notices were sent out on September 17th, 2025, then a second wave was sent out nearly six months later in March.

 

In the know

Although ApolloMD never officially confirmed the cause of the attack, ransomware group Qilin claimed the incident and added the company to its Tor-based leak site in June of 2025, as noted by Security Week. According to the Office of Information Security (OIS), Qilin first began operating a ransomware-as-a-service (RaaS) platform in 2022, specifically targeting healthcare organizations. It’s believed the group originates from Russia. While ApolloMD didn’t elaborate on how they were attacked, Qilin generally uses spear phishing techniques, meaning they impersonate trusted individuals to target employees, and often deploy remote monitoring and management software to gain control of a network.

As a RaaS group, Qilin provides ransomware tools to affiliates in exchange for 15-20% of the proceeds. According to the OIS, they generally demand ransoms between $50,000-$80,000, although it’s unclear what they demanded from ApolloMD, and if they received anything.

 

The big picture

In June 2026, Paubox wrote on the leading ransomware gangs targeting healthcare, and Qilin easily took a spot, having attacked healthcare organizations over 70 times. Groups like Qilin, but also The Gentleman, Interlock, and ShinyHunters, are likely why Paubox has found that ransomware attacks on healthcare have surged approximately 264% since 2018. While healthcare organizations think about the best way to prepare and respond to attacks, it’s worth paying attention to major players’ strategies, which frequently include forms of phishing. Even though phishing is getting harder and harder to prevent (a Microsoft report found that AI makes phishing 4.5 times more effective and profitable), the right software is still highly effective. Paubox’s email suite takes human error out of the equation and continually adapts to evolving trends in cybersecurity, which is probably one of the reasons why we’ve never experienced a data breach.

 

FAQs

Why were breach notices sent out in “batches?”

ApolloMD didn’t provide a reason for sending out the notices in batches, especially so far apart from each other, but it’s likely that they were still investigating the incident and may have not known the full amount of people impacted or what data of theirs was impacted.

 

What is Tor?

Tor, which is short for The Onion Router, is a decentralized network of servers that allow the user to maintain anonymity when accessing regular websites. It’s similar to a VPN, as both are used for anonymity, although Tor uses a distributed network which means it’s even harder to trace. Ransomware gangs use tools like this to make it difficult for their illegal activity to be traced to individuals. Although Tor is sometimes used for illegal activity, it’s also a tool that gained support from some privacy activists and journalists.