ApolloMD, a US-based healthcare services and practice management provider and HIPAA business associate, disclosed that a May 2025 cyberattack led to unauthorized access to its IT environment and potential theft of patient data affecting 626,540 individuals. ApolloMD reported detecting unusual activity on May 22, 2025, and its investigation concluded an unauthorized party accessed systems between May 22–23, 2025, including files tied to patients treated by affiliated physicians and practices; the incident was later reflected in US HHS breach reporting.
Exposed data varied by individual but included names, dates of birth, addresses, diagnoses, treatment details/dates of service, provider names, health insurance information, and for some, Social Security numbers. Reporting also linked the incident to the Qilin ransomware group, which publicly listed ApolloMD on its leak site in June 2025 and claimed exfiltration of 238 GB (posting limited proof screenshots not showing patient data); ApolloMD’s public notice did not confirm ransomware, encryption, or a ransom demand. ApolloMD notified affected client practices between July–September 2025, issued patient letters in mid-September 2025, and posted a substitute notice later that month, including a list of impacted managed physician practices.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
By 2026-02-12, ApolloMD had published a public substitute notice describing the May 2025 incident and the affected data. The notice did not mention ransomware, encryption, or any ransom demand.
ApolloMD later reported the breach to the US Department of Health and Human Services, disclosing that 626,540 individuals were affected. This formal reporting established the scale of the incident in public breach records.
ApolloMD began sending notification letters to affected patients on 2025-09-17. The notices said the incident may have exposed varying combinations of personal and protected health information, including Social Security numbers in some cases.
Between 2025-07-21 and 2025-09-11, ApolloMD notified its managed physician practices and client organizations about the breach. These notifications concerned potential exposure of patient information tied to affiliated physicians and practices.
On 2025-06-12, the Qilin ransomware group publicly claimed responsibility for the ApolloMD incident. The group alleged it had exfiltrated 238 GB of data and posted limited proof screenshots, though no patient data dump was apparent.
ApolloMD identified unusual activity in its IT environment on 2025-05-22, engaged a digital forensics firm, and notified law enforcement. The company later determined unauthorized access occurred between 2025-05-22 and 2025-05-23.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.