ApolloMD Pays $4 M Settlement After Qilin Ransomware Group Exfiltrates PHI of 627 K Patients
What Happened – In May 2025 the Qilin ransomware gang breached ApolloMD Business Services, a revenue‑cycle management vendor for physician practices. The attackers accessed the firm’s IT environment for roughly 24 hours, exfiltrating 238 GB of protected health information (PHI) that included names, dates of birth, Social Security numbers, diagnoses, treatment dates and insurance details for 626,540 patients. The fallout resulted in a proposed class‑action settlement of just over $4 million.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a third‑party breach that SOC 2’s vendor‑risk criteria (CC6.1, CC6.2) are designed to detect, monitor, and evidence.
- Continuous monitoring and audit‑ready documentation of a vendor’s security posture can provide the defensible trail needed to demonstrate due diligence to regulators and auditors.
- Leveraging a platform that aggregates vendor assessments, SOC 2 reports, and real‑time breach alerts helps organizations stay ahead of similar supply‑chain threats.
Who Is Affected – Healthcare providers, physician practices, and any organization that relies on ApolloMD’s revenue‑cycle services for patient billing and data handling.
Recommended Actions
- Update your vendor‑risk program to incorporate the latest breach intelligence on ApolloMD and require a current SOC 2 Type II report.
- Collect and archive evidence of third‑party security controls (penetration‑test results, incident‑response plans, continuous‑monitoring logs) to satisfy audit requirements.
Source: DataBreachToday – Services Firm ApolloMD Settles Hack Lawsuit for $4M
Technical Notes – Attack vector: ransomware‑malware deployment by the Qilin gang; data exfiltrated: 238 GB of PHI (names, DOB, SSNs, diagnoses, treatment dates, insurance information). No specific CVE disclosed. Source: same as above