What Is This Settlement?
ApolloMD will pay $4.02 million to settle claims it failed to prevent a May 2025 data breach that exposed patient information. Class members can take a flat $75 or claim up to $5,000 in documented losses, and everyone gets a year of medical data monitoring.
ApolloMD is an Atlanta-based physician group that hospitals hire to run entire departments. It describes itself as a private, independent practice with no outside shareholders, owned by the physicians and advanced practice clinicians who work in it, and it staffs emergency medicine, hospital medicine, anesthesia and radiology across more than 100 healthcare institutions nationwide. Its own materials put average annual emergency department volume at over 40,000 visits per client hospital, which is the scale that explains how a single company ends up holding records for hundreds of thousands of patients who never chose it. Its name isn’t on the hospital sign either, and where patients see it at all it is usually on a separate physician bill rather than the hospital’s.
The breach itself was a cyberattack on ApolloMD’s network in May 2025. A ransomware group publicly claimed credit and threatened to publish the stolen data on the dark web, and it isn’t known whether a ransom was paid. Reporting on the notification puts the number of people affected at around 626,000, while the settlement notice describes roughly 662,000 — either way it is one of the larger healthcare breaches of the year.
Who Qualifies?
The class covers anyone who received a notice from ApolloMD saying their information may have been compromised in the May 2025 breach.
What You Can Claim
Three benefits sit in this settlement, and the first two are alternatives rather than a package.
Documented losses, up to $5,000. Covers fraudulent charges, identity theft, money spent on credit monitoring, and similar out-of-pocket costs traceable to the breach.
A flat $75 instead. The figure adjusts up or down pro rata depending on how many claims arrive, so $75 is the target rather than a floor.
A year of medical data monitoring, available to all class members. It includes real-time credit monitoring, dark web scanning, $1 million in identity theft insurance, and access to fraud resolution agents.
The monitoring is the part people skip, and on a healthcare breach it’s arguably worth more than the cash. Medical records don’t expire the way a card number does — a stolen card is cancelled in a day, while a date of birth, an insurance ID and a diagnosis stay valid for years.
What Counts as Proof
Acceptable: telephone records, correspondence, receipts, bank statements, emails, and other third-party documentation of what the breach cost you.
Not acceptable on their own: personal certifications, declarations, or affidavits. Writing a sworn statement describing your losses does not by itself meet the standard. Such a statement can be submitted alongside real documentation to explain or contextualize it, but it cannot replace it.
That rule is what separates the two tiers in practice.
How to File
Claims go through the settlement administrator at ApolloMDDataSettlement.com, with Kroll Settlement Administration handling the process.
The claim deadline is September 30, 2026. Filing requires the Class Member ID printed on your notice. If the letter is gone, Kroll can supply the number on 833-930-0984, or by post at P.O. Box 5324, New York, NY 10150-5324.
Have your documentation to hand before you start if you’re claiming losses, since a part-finished claim is easy to abandon.
The Deadline That Comes First
August 31 is the one to act on first, because mixing the two dates up costs you a right rather than a payment.
Opting out is the only way to keep your ability to sue ApolloMD separately over this breach. It also forfeits every benefit here, including the monitoring.
Objecting tells the court you think the settlement is inadequate, and it doesn’t prevent you from also filing a claim.
When Would Payments Arrive?
The final approval hearing is October 5, 2026. Nothing pays out before a judge approves the settlement, and an appeal by any objector pushes it further.
Filing early doesn’t accelerate payment; it only removes the risk of missing the date.
What the Lawsuit Alleged
The complaint said ApolloMD failed to implement reasonable cybersecurity measures, and that the failure is what allowed the attack to succeed.
No court has ruled on the allegations, and the settlement resolves the case without any finding on the merits.
Class counsel are Jeff Ostrow of Kopelowitz Ostrow and Casondra Turner of Milberg.
Should You Take the $75 or Claim Losses?
The answer is usually determined by your paperwork rather than by your preference.
Take the $75 if the breach caused you inconvenience and worry but nothing you can evidence with a document from a third party.
Claim documented losses if you can point to specific charges, specific costs, or specific time and money spent fixing something.
The monitoring is available either way.
Frequently Asked Questions
I think I got the letter but I’ve lost it. Can I still file?
Contact Kroll on 833-930-0984 and explain. Class membership here rests on ApolloMD having identified you and sent notice, which means the administrator works from a list rather than from your copy of the letter.
Why did a company I’ve never heard of have my medical data?
Because patient records flow to the physician’s employer for billing and clinical documentation, not only to the hospital where you were treated.
Does taking the $75 stop me claiming later if fraud shows up?
Yes, and so does taking nothing. The release binds every class member who doesn’t opt out, whether or not they file, so declining the $75 preserves nothing. Opting out by August 31 is the only route that keeps a later claim alive.
Is the credit monitoring worth signing up for if I already have some?
Possibly not, though this one includes dark web scanning and $1 million of identity theft insurance, which basic card-issuer monitoring often doesn’t. Compare what you already have rather than assuming duplication.
My child was treated in an ER. Can I claim for them?
If a notice was issued in the child’s name, the claim belongs to that child and a parent or guardian would file it. Children’s records are attractive in breaches precisely because misuse can go unnoticed for years, which is worth weighing on the monitoring option.
What happens if more people claim than expected?
The $75 payment adjusts pro rata, so a heavy response lowers it. Documented loss claims are paid on what you evidence, up to $5,000, so they behave differently from the flat payment.
About This Page
RecallRefunds.com is a consumer information site. We are not the settlement administrator, a law firm, a court, or ApolloMD, and we cannot file, check, or expedite a claim. This page summarizes a proposed class action settlement and is general information rather than legal advice. The allegations are unproven and ApolloMD denies them. The settlement website and Kroll Settlement Administration control on all questions of eligibility, deadlines and payment.
