ApolloMD Data Breach Exposes 626,540 Patients: Qilin Ransomware Attack Confirmed
A May 2025 cyberattack compromised sensitive health data for 626,540 individuals at ApolloMD. Hackers accessed files between May 22-23 containing names, addresses, birth dates, diagnoses, treatment details, provider info, and insurance data. Some Social Security numbers were also stolen
Atlanta-based ApolloMD manages physician services across 125 practices in 18 states. The company serves over 2,500 doctors and advanced clinicians. Qilin ransomware claimed responsibility by listing ApolloMD on its Tor leak site in early June 2025.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
ApolloMD posted a substitute notice detailing the breach scope. Notifications went to affiliated physicians by September 2025. Affected patients received mailed letters with free credit monitoring services.
HHS added ApolloMD to its public breach portal this week, confirming the massive scale. The incident ranks among largest healthcare breaches of 2025.
Healthcare remains prime ransomware target due to valuable patient data. Qilin specializes in double extortion attacks hitting hospitals and clinics nationwide.
Official Breach Disclosures
HHS OCR Portal: Lists 626,540 impacted individuals from May 22-23, 2025 incident OCR Breach Report
Stolen Data Categories
| Data Type | Impact Level | Recovery Steps |
|---|---|---|
| Names/Addresses | High | Credit monitoring |
| DOB/Diagnoses | Critical | Identity theft risk |
| Treatment Details | Critical | Medical fraud risk |
| Insurance Info | High | Billing fraud risk |
| Social Security # | Critical | Full identity protection |
Company Profile
- Location: Atlanta, Georgia
- Services: Physician practice management
- Coverage: 125 practices, 18 states
- Staff: 2,500+ physicians/APCs
- Breach Date: May 22-23, 2025
Timeline of Events
- May 22-23: Unauthorized file access
- Early June: Qilin adds to leak site
- September: Physician notifications
- September: Patient mailings begin
- February 2026: HHS portal listing
Ransomware Threat Profile
Qilin emerged 2024 targeting healthcare. Uses double extortion with data theft plus encryption. Hits hospitals, clinics across US. Refuses negotiations per US policy.
Patient Protection Measures
Free credit monitoring offered. Mailed notification letters dispatched. HHS portal provides breach verification. Patients urged to monitor medical statements.
Healthcare Breach Context
Healthcare accounts for 20%+ of major US breaches annually. Patient data sells for $50-$1000/record on dark web. Ransomware groups increasingly target medical networks.
FAQ
626,540 individuals
PII, PHI, SSNs
Qilin leak site June 2025
Physicians September 2025, patients by mail
Atlanta-based, 125 practices across 18 states
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages