Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

ApolloMD Data Breach Impacts 626,000 Individuals

The company says hackers stole the personal information of patients of affiliated physicians and practices.

Healthcare data breach

Over 626,000 individuals were impacted by a May 2025 cyberattack at healthcare physician and practice management services provider ApolloMD.

The incident occurred between May 22 and May 23 and involved access to files containing personally identifiable information (PII) and protected health information (PHI) pertaining to affiliated physicians and practices.

In an incident notice on its website, the company revealed that the hackers stole names, addresses, dates of birth, diagnostic details, provider names, dates of service, treatment information, and health insurance information.

“For some individuals, the incident may have also involved their Social Security numbers,” ApolloMD’s notice reads (PDF).

By September 2025, the company had notified the affiliated physicians and practices of the incident and had started mailing notification letters to the impacted individuals, providing them with free credit monitoring services.

This week, the US Department of Health and Human Services listed the firm on its data breaches portal, revealing that 626,540 individuals were impacted.

Advertisement. Scroll to continue reading.

ApolloMD has not shared details on the threat actor responsible for the attack, but the Qilin ransomware group added the company to its Tor-based leak site in early June 2025.

Based in Atlanta, Georgia, ApolloMD provides integrated, multispecialty physician, practice, and advanced practice clinician (APC) management services to over 125 practices across 18 states. It works with more than 2,500 physicians and APCs.

Related: Crunchbase Confirms Data Breach After Hacking Claims

Related: Under Armour Looking Into Data Breach Affecting Customers’ Email Addresses

Related: 750,000 Impacted by Data Breach at Canadian Investment Watchdog

Related: Central Maine Healthcare Data Breach Impacts 145,000 Individuals

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Doppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.

Delinea has appointed Timothy Regan as Chief Financial Officer.

Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.