ApolloMD Agrees to Pay $4.02M to Settle Data Breach Lawsuit

ApolloMD Business Services, a business associate that provides integrated, multispecialty physician, APC, and practice management services, has agreed to settle a class action lawsuit stemming from a May 2025 ransomware attack.

The attack was identified by ApolloMD on or around May 22, 2025, and the forensic investigation determined that a ransomware actor accessed its network between May 22 and May 23, 2025, potentially exfiltrating files containing the protected health information of patients of its healthcare provider clients. The Qilin ransomware group claimed responsibility for the attack.

The ApolloMD data breach included names, dates of birth, health information, health insurance information, and for some individuals, Social Security numbers, and was reported to the HHS’ Office for Civil Rights as affecting 626,540 individuals. The first batch of notification letters was mailed to the affected individuals starting in September 2025, with a second wave of notifications issued in March 2026.

The first class action lawsuits were filed shortly after the first round of notification letters were issued. In January 2026, the court granted the motion to consolidate the lawsuits into a single complaint – In re ApolloMD Data Breach Litigation – which was filed in the U.S. District Court for the Northern District of Georgia, Atlanta Division.

The consolidated lawsuit alleged that the ransomware attack occurred as a result of the failure of the defendant to implement reasonable and appropriate cybersecurity measures. ApolloMD denies all claims and contentions asserted in the action, including any wrongdoing and liability. Following mediation in January 2026, the parties agreed on the material terms of a settlement, which has now been finalized and has received preliminary approval from the court.

The defendant has agreed to establish a $4,020,000 settlement fund to pay benefits to the class members, after attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives have been deducted. All class members are entitled to a one-year membership to a CyEx medical data monitoring service and may claim one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member. Alternatively, a pro rata cash payment may be claimed, estimated at $75 per claimant. The cash payments will be subject to a pro rata increase or decrease depending on the number of claims received.

The deadline for objection and opting out is August 31, 2026. Claims must be submitted by September 30, 2026, and the final fairness hearing has been scheduled for October 5, 2026.

The post ApolloMD Agrees to Pay $4.02M to Settle Data Breach Lawsuit appeared first on The HIPAA Journal.

HHS Seeks Input on Potential Updates to the CLIA Regulations

The HHS’ Centers for Medicare and Medicaid Services (CMS) and the Centers for Disease Control and Prevention (CDC) have issued a request for information (RFI) on potential updates to the Clinical Laboratory Improvement Amendments (CLIA) of 1988. The RFI covers several topics, including breath testing, laboratory processes and procedures, emergency preparedness, cybersecurity, and the use of artificial intelligence. The feedback received in response to the RFI will advise future actions and rulemaking. Comments are being accepted through September 14, 2026.

The CLIA regulations were enacted on October 31, 1988, strengthening federal oversight of clinical laboratories and helping to ensure the accuracy and reliability of patient test results. The CLIA regulations were promulgated in 1992, and while certain elements of the CLIA regulations have been updated over the years, a substantial update may be required to better reflect current knowledge and advancements in laboratory testing.

One area where updates may be required is cybersecurity, as threats across the healthcare sector have expanded significantly in both scope and severity. “As clinical laboratories increasingly rely on digital systems and connected technologies—such as Laboratory Information System (LIS), Electronic Health Record (EHR) integration, automated diagnostic devices, and virtual or remote access to laboratory and patient data—new cybersecurity risks have emerged,” explained the CMS and CDC in the RFI.

Many U.S. laboratories are HIPAA-regulated entities and must therefore comply with the requirements of the HIPAA Security Rule; however, there are gaps that need to be addressed and threats that the current HIPAA Security Rule does not adequately protect against. The CMS is seeking non-proprietary/non-confidential information on current laboratory cybersecurity practices and experiences related to protecting patient data and lab operations; user identity and access; remote access to systems containing personal information from overseas entities; restrictions on ports and/or internet protocol (IP) addresses; cybersecurity response plans; and cybersecurity training.

One area where further regulation is likely required is artificial intelligence, as the CLIA regulations were enacted long before AI tools started to be used in clinical settings. Model corruption, hallucinations, and compromises could have serious implications for the accuracy and reliability of testing. The CMS and CDC are seeking information on postanalytic interpretation and the use of AI tools, specifically, the algorithms and AI tools used in postanalytic analysis; the circumstances where software and AI tools are being used to interpret test results, histopathology slides, and results; the methods used to verify the performance of those tools; and whether there are any additional technology considerations for high complexity tests that the CMS and CDC should consider incorporating into the CLIA regulations.

The post HHS Seeks Input on Potential Updates to the CLIA Regulations appeared first on The HIPAA Journal.

23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit

A coalition of 42 state attorneys general has agreed to a $18 million settlement with 23andMe (now Chrome Holding Co.) to resolve alleged cybersecurity failures that led to an October 2023 data breach affecting 6.9 million of its customers. The settlement also includes a commitment to implement new data security measures to better secure consumer data and prevent further data breaches.

The 23andMe data breach occurred as a result of credential stuffing, which is where credentials obtained in a data breach at one or more companies are used to try to gain access to accounts on an unrelated platform. These attacks can only succeed if individuals reuse the same credentials across multiple accounts. When the credential stuffing campaign was discovered, 23andMe maintained that there had not been a breach, and that the compromised accounts were the result of customers’ poor security practices.

While 23andMe customers took risks by reusing their credentials on the 23andMe site, the multistate investigation found that 23andMe was at fault as the company lacked basic cybersecurity measures for preventing credential-based attacks. For instance, 23andMe did not compare users’ passwords against blocklists of known breached passwords, did not require multifactor authentication, and did not have rate limiting or intrusion prevention measures in place. Further, there was insufficient logging and monitoring, which allowed the credential-stuffing campaign to go unnoticed for five months between April 2023 and September 2023, and a failure to investigate and address unusual login patterns, such as a massive spike in login attempts indicative of a credential stuffing campaign. The investigation also identified a failure to fix known vulnerabilities and properly review and test design features of its platform.

23andMe filed for bankruptcy protection in March 2025, and the company’s data was sold to TTAM Research, a company formed by 23andMe founder and former CEO, Anne Wojcicki. The coalition sued 23andMe during the company’s bankruptcy, and the new data security requirements apply to TTAM, which is now registered as 23andMe Research Institute. The $18 million settlement will be paid to the participating states, with New York due to receive more than $705,000.

“Companies have a duty to protect their customers’ personal information from hackers, but 23andMe put millions of its customers at risk with its flimsy security measures,” said Attorney General James. “New Yorkers trusted 23andMe with their sensitive and personal genetic data, only to find that data stolen and put up for sale on the dark corners of the internet. As a result of our coalition’s action, 23andMe will pay for violating the law, and strict rules will be put in place to protect their customers.”

23andMe has previously agreed to pay $46.75 million as compensation to victims of the data breach, and has previously been fined by data protection watchdogs in Spain ($2.75M) and the United Kingdom ($3.1M) over the data breach. California did not participate in the multistate action, having filed its own lawsuit; however, a bankruptcy judge ruled this month that the state cannot seek monetary relief due to its Chapter 11 reorganization plan.

The post 23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit appeared first on The HIPAA Journal.

Abbott Investigating Cyberattack Claims From Two Threat Actors

The healthcare giant Abbott is investigating claims from two threat groups who allege cyberattacks and data theft, one involving legacy Exact Sciences systems of its cancer diagnostics business, and another involving its LabCentral portal.

Abbott acquired Exact Sciences in late 2025, a company specializing in cancer screening and precision oncology diagnostics. The acquisition allowed the company to enter the fast-growing cancer diagnostics market. Abbott has yet to confirm the extent to which patient data has been compromised but has confirmed unauthorized access to certain legacy cancer diagnostics systems. The intrusion did not impact any other Abbott businesses, and had no impact on its business operations, products, product availability, manufacturing/lab operations, or its ability to serve patients. The impacted Exact Sciences systems are separate from Abbott’s systems. In a July 16, 2026, announcement, Abbott said it does not anticipate the incident having any material impact on the business or its financial results.

The ShinyHunters data theft and extortion group claimed responsibility for the attack and threatened to publish the stolen data if payment was not made. Abbott negotiated with the group, and the publication deadline was extended to July 21, 2026. It is currently unclear if payment has been made, and as of July 20, 2026, the stolen data has not been leaked.

ShinyHunters often compromises victims’ systems through voice phishing (vishing) and appears to have used those tactics in this attack. Bleeping Computer reports that it received communications from a ShinyHunters spokesperson stating vishing attacks were conducted on Abbott employees in mid-June, which allowed the group to compromise a Microsoft Entra single sign-on account that provided access to certain internal systems. The group claims to have exfiltrated 30 million rows of customer data, including names, contact information, dates of birth, and one million Social Security numbers.

An investigation has also been launched into a separate claim from a hacker with the moniker ShadowByt3$. This separate attack, so the hacker claims, involved unauthorized access to the Abbott core business via the LabCentral customer portal. The threat actor claims to have gained access on July 4, 2026, using compromised customer credentials, exfiltrating data over the weekend, although no customer or patient data was compromised. Abbott maintains that the third-party hosted portal does not contain sensitive data, only publicly available, non-sensitive data, such as technical product reference documents including operating manuals, product specifications, and troubleshooting checklists.

Abbott is one of several medtech companies to announce cyberattacks and data breaches in recent months, including Stryker, Medtronic, iRhythm, AdaptHealth, and Intuitive.

The post Abbott Investigating Cyberattack Claims From Two Threat Actors appeared first on The HIPAA Journal.