ApolloMD pays $4.02M to settle data breach lawsuit over Qilin attack

ApolloMD agrees to pay $4.02M to settle a class action lawsuit after a Qilin ransomware attack exposed 626,000 patient records.

MedRisk Staff
By
2 Min Read

The $4.02M ApolloMD settlement offers a window into how ransomware lawsuits against healthcare business associates are resolving in 2026. A federal judge’s preliminary approval of the deal means more than 626,000 patients could receive compensation after Qilin ransomware operators breached the practice management firm last May.

Patients have two paths to recovery under the proposed settlement. They can claim reimbursement for out-of-pocket losses directly tied to the breach up to $5,000, or accept a smaller pro rata cash payment estimated at $75 per claimant. The settlement also funds a year of medical data monitoring through CyEx. These dual options mirror a pattern emerging in healthcare data breach class actions, where courts push for both compensatory and prophylactic relief.

The timeline matters for compliance teams watching this space. ApolloMD detected the intrusion on May 22, 2025, notified patients starting September 2025, and reached a mediated settlement by January 2026. The roughly eight months from breach discovery to settlement framework is faster than many comparable healthcare cases, which often stretch into multi-year litigation. Court watchers note the Qilin ransomware group’s known track record of data exfiltration likely accelerated the settlement calculus.

ApolloMD denies liability but the settlement carries binding security commitments for the Atlanta-based firm. While the company has not disclosed what specific cybersecurity changes it will implement, most comparable settlements require updated access controls, network monitoring, and employee training programs. The objection window closes August 31, with a final fairness hearing set for October 5.

For healthcare CISOs, the case reinforces that ransomware attacks on business associates carry litigation exposure regardless of whether the vendor directly serves patients. ApolloMD’s role as a physician and practice management intermediary still triggered class action liability under state data breach statutes.

Share This Article