Apria Healthcare LLC
bd_0c096a0a3641dc00 · schema v1 · pii pii-v1
Full breach record for Apria Healthcare LLC →Apria Healthcare (CA, healthcare provider) reported to HHS OCR on 2016-10-04 that a workforce member fell for a phishing scam, granting unauthorized access to her work email account. Approximately 1,987 individuals were potentially affected. PHI involved included names, Social Security numbers, dates of birth, driver's license numbers, medical record numbers, diagnoses, and other clinical information. The CE notified affected individuals, HHS, and the media; provided free credit monitoring; revised policies and procedures; and trained workforce on phishing. OCR provided technical assistance and obtained assurances of corrective actions.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_030aa96547f5e4daNew Hampshire State AGfiled 2016-10-20(16d gap)Candidate
- bd_bea31cb8de986371California State AGfiled 2016-10-20(16d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 4, 2016
- Raw hash
- 8822b08162ae5c386f1b6c11f57e6d97ad2a1e47afbbc5b6a0616b37e7b04f64
Source filing
Reporting entity
- Name
- Apria Healthcare LLCnorm: apria healthcare
- Domain
- apria.com
Victim entity
- Name
- Apria Healthcare LLCnorm: apria healthcare
- Domain
- apria.com
- Industry
- Healthcare Provider
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- Oct 4, 2016
- Affected individuals
- 1,987
- Data types
- PHIPIIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Phishing
- Threat actor
- External
- Regulator citations
- HHS OCR breach report filed 2016-10-04OCR provided substantial technical assistanceMedia notification provided
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: Oct 4, 2016— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.