HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

ApolloMD Pays $4M Settlement After Qilin Ransomware Group Exfiltrates PHI of 627,000 Patients

In May 2025, Qilin ransomware gang accessed ApolloMD’s systems and stole 238 GB of protected health information affecting 627 K patients. The breach led to a $4 M class‑action settlement, underscoring the need for robust vendor‑risk controls and SOC 2 evidence.

LiveThreat™ Intelligence · 📅 July 22, 2026· 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
databreachtoday.com

ApolloMD Pays $4 M Settlement After Qilin Ransomware Group Exfiltrates PHI of 627 K Patients

What Happened – In May 2025 the Qilin ransomware gang breached ApolloMD Business Services, a revenue‑cycle management vendor for physician practices. The attackers accessed the firm’s IT environment for roughly 24 hours, exfiltrating 238 GB of protected health information (PHI) that included names, dates of birth, Social Security numbers, diagnoses, treatment dates and insurance details for 626,540 patients. The fallout resulted in a proposed class‑action settlement of just over $4 million.

Why It Matters for Compliance & Audit Readiness

  • The incident is a textbook example of a third‑party breach that SOC 2’s vendor‑risk criteria (CC6.1, CC6.2) are designed to detect, monitor, and evidence.
  • Continuous monitoring and audit‑ready documentation of a vendor’s security posture can provide the defensible trail needed to demonstrate due diligence to regulators and auditors.
  • Leveraging a platform that aggregates vendor assessments, SOC 2 reports, and real‑time breach alerts helps organizations stay ahead of similar supply‑chain threats.

Who Is Affected – Healthcare providers, physician practices, and any organization that relies on ApolloMD’s revenue‑cycle services for patient billing and data handling.

Recommended Actions

  • Update your vendor‑risk program to incorporate the latest breach intelligence on ApolloMD and require a current SOC 2 Type II report.
  • Collect and archive evidence of third‑party security controls (penetration‑test results, incident‑response plans, continuous‑monitoring logs) to satisfy audit requirements.

Source: DataBreachToday – Services Firm ApolloMD Settles Hack Lawsuit for $4M

Technical Notes – Attack vector: ransomware‑malware deployment by the Qilin gang; data exfiltrated: 238 GB of PHI (names, DOB, SSNs, diagnoses, treatment dates, insurance information). No specific CVE disclosed. Source: same as above

📰 Original Source
https://www.databreachtoday.com/services-firm-apollomd-settles-hack-lawsuit-for-4m-a-32281

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →