HackingCustomer Data InvolvedTargetedPIIIDENTITY_BASICCREDENTIALSMediumContained
Apria Healthcare LLC
bd_95d978c59636df32 · schema v1 · pii pii-v1
Full breach record for Apria Healthcare LLC →Apria Healthcare LLC notified New Hampshire residents of a security incident where an unauthorized third party accessed systems containing personal information between April 2019 and October 2021. The actor's intent was financial fraud; no evidence of funds removal or data exfiltration was found. 8,566 NH residents were affected. Apria engaged the FBI and forensic investigators, implemented security measures, and offered 12 months of Kroll identity protection services.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_484942091b9acd62Oregon State AGfiled 2023-05-22(9d gap)Candidate
- bd_a0195e3f90a18f77Delaware State AGfiled 2023-05-22(9d gap)Verified
- bd_a2be55087df28190Maine State AGfiled 2023-05-22(9d gap)Verified
- bd_b9bdb6b76ef4907eDelaware State AGfiled 2023-05-22(9d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 9d gap
- bd_c1a512d17d99444fMontana State AGfiled 2023-05-22(9d gap)Verified
- bd_ca14fb87d20497f2California State AGfiled 2023-05-22(9d gap)Verified
- bd_e12921387568e40fWashington State AGfiled 2023-05-22(9d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/apria-healthcare-20230531.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 31, 2023
- Raw hash
- cc9b6c4364e3df650cbefec2cd6db0ee09cabdac535e107b830421ac85224c3f
Reporting entity
- Name
- Apria Homenorm: apria home
- Domain
- apriahome.com
Victim entity
- Name
- Apria Healthcare LLCnorm: apria healthcare
- Domain
- apria.com
Incident
- Discovered
- Sep 1, 2021
- Materiality determined
- —
- Notification sent
- May 22, 2023
- Affected individuals
- 8,566
- Data types
- PIIIDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- working with the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 months(637 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.