Apria Healthcare LLC
bd_0c096a0a3641dc00 · schema v1 · pii pii-v1
Full breach record for Apria Healthcare LLC →6 incidents on fileApria Healthcare (CA, healthcare provider) reported to HHS OCR on 2016-10-04 that a workforce member fell for a phishing scam, granting unauthorized access to her work email account. Approximately 1,987 individuals were potentially affected. PHI involved included names, Social Security numbers, dates of birth, driver's license numbers, medical record numbers, diagnoses, and other clinical information. The CE notified affected individuals, HHS, and the media; provided free credit monitoring; revised policies and procedures; and trained workforce on phishing. OCR provided technical assistance and obtained assurances of corrective actions.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 5, 2016
Begins
Oct 4, 2016
Filed
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- New Hampshire State AGbd_030aa96547f5e4da2016-10-20 · +16dCandidate
- California State AGbd_bea31cb8de9863712016-10-20 · +16dVerified
Filing propagation · 3 filings · 2 states
View merged incident ↗Pattern: first filing Oct 4 (CA), last Oct 20 (CA) — a 16-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.