Physician Wound Solutions, LLC dba Apollo Medical Supply Data Breach
Apollo Medical Supply Network Server Breach Affects 3,561 Patients
What happened in the Physician Wound Solutions, LLC dba Apollo Medical Supply data breach?
The Physician Wound Solutions, LLC dba Apollo Medical Supply data breach was reported on April 29, 2025 and affected 3,561 individuals. The breach type was Unauthorized Access/Disclosure involving Network Server. This breach occurred in Florida. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Physician Wound Solutions, LLC dba Apollo Medical Supply Breach Details
Physician Wound Solutions, LLC, operating under the business name Apollo Medical Supply, experienced an unauthorized access incident involving its network server infrastructure. The breach was reported to the Florida Department of Health on April 29, 2025, and potentially exposed protected health information (PHI) belonging to 3,561 individuals. The unauthorized access to the network server represents a significant security incident for this medical supply company, which serves patients across Florida with wound care products and related healthcare services.
Company Response
Upon discovery of the unauthorized access to their network server, Physician Wound Solutions initiated an investigation to determine the scope and nature of the breach. The company worked to identify which patient records were accessed without authorization and began the process of notifying affected individuals as required under the Health Insurance Portability and Accountability Act (HIPAA). The breach was formally reported to state health authorities on April 29, 2025, triggering mandatory notification procedures. The company's response included securing the affected network infrastructure and conducting a comprehensive review of access logs to determine what information may have been compromised.
Specific Details
Network server breaches typically occur through one or more of several common vectors: exploitation of unpatched software vulnerabilities, weak authentication credentials, misconfigured access controls, or compromised employee credentials. The location designation of "Network Server" indicates that the breach occurred at the infrastructure level rather than at a single workstation or portable device. This suggests the unauthorized access may have provided broad exposure to multiple patient records stored on networked systems. Network server compromises are particularly concerning because they can potentially affect large volumes of data simultaneously and may indicate a more sophisticated attack than isolated device theft. The breach classification as "Unauthorized Access/Disclosure" indicates that an unauthorized party gained entry to systems containing PHI, and there is evidence or reasonable concern that information was viewed or extracted.
Organizational Context
Physician Wound Solutions, LLC operates Apollo Medical Supply as a medical supply company focused on wound care products and services. The company serves patients throughout Florida, providing essential medical supplies and related healthcare support. As a medical supply company handling patient information, Apollo Medical Supply is subject to HIPAA regulations and must maintain appropriate safeguards for all protected health information. The involvement of a business associate in this breach indicates that the company may have engaged third-party vendors or service providers who had access to patient data, adding complexity to the breach investigation and notification process.
Number of People Affected
The breach impacted 3,561 individuals whose information was stored on the compromised network server. This patient population represents customers and clients of Apollo Medical Supply who had provided personal and health information as part of receiving medical supply services. Each affected individual is entitled to notification of the breach and information about steps they can take to protect themselves from potential misuse of their information.
Personal Information Involved
While the specific data elements exposed have not been detailed in the breach submission, network server breaches at medical supply companies typically expose multiple categories of protected health information. Likely exposed data may include: patient names, dates of birth, medical record numbers, addresses, telephone numbers, email addresses, insurance information including policy numbers and group numbers, diagnosis codes and medical history related to wound care conditions, treatment information and clinical notes, prescription information, and potentially Social Security numbers or other government-issued identification numbers. The actual scope of exposed information depends on what data fields were stored on the compromised server and what access the unauthorized party obtained.
Patient Impact and Notifications
All 3,561 affected individuals were required to receive notification of the breach in accordance with HIPAA's Breach Notification Rule. This rule mandates that covered entities and business associates notify individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured PHI. Notifications typically include a description of the breach, the types of information involved, steps individuals should take to protect themselves, what the organization is doing to investigate and prevent future breaches, and contact information for questions. Patients should have received these notifications by late June 2025, assuming the breach was discovered shortly before the April 29, 2025 submission date.
Industry Context and HIPAA Implications
Network server breaches represent a significant category of healthcare data breaches, accounting for a substantial portion of incidents reported to the Department of Health and Human Services. According to HHS breach notification data, unauthorized access incidents affecting healthcare organizations have increased in frequency and sophistication over recent years. Medical supply companies, while sometimes receiving less attention than hospitals or large health systems, handle sensitive patient information and are equally subject to HIPAA requirements. The involvement of a business associate in this breach highlights the importance of vendor management and ensuring that all parties handling PHI maintain appropriate security measures. HIPAA requires covered entities to conduct risk assessments, implement administrative, physical, and technical safeguards, and maintain audit controls to detect and respond to unauthorized access. Network server security is a critical component of these safeguards, requiring regular patching, strong access controls, encryption, and continuous monitoring. This incident serves as a reminder that healthcare organizations of all sizes must maintain strong cybersecurity practices to protect patient information from increasingly sophisticated threats.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Physician Wound Solutions, LLC dba Apollo Medical Supply Breach
Monitor credit reports from all three major bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze if concerned about identity theft risk
Review explanation of benefits (EOB) statements and medical bills for unauthorized services or claims; contact your insurance provider and healthcare providers if you identify suspicious activity
Monitor your medical records for unauthorized access or changes; request copies of your medical records from Apollo Medical Supply and your healthcare providers to verify accuracy
Be cautious of unsolicited communications claiming to be from healthcare providers or insurance companies; do not provide personal information in response to unexpected calls or emails, and verify contact information independently before responding
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Florida Breaches
Search all breaches reported in Florida