HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Apria Healthcare LLC
bd_bea31cb8de986371 · schema v1 · pii pii-v1
Full breach record for Apria Healthcare LLC →On August 5, 2016, Apria Healthcare discovered unauthorized access to an employee's email account. The incident potentially exposed personal and medical information, including names, dates of birth, Social Security numbers, and diagnosis information, for 912 California residents. Apria Healthcare engaged forensic experts, changed credentials, and offered 12 months of credit monitoring. No evidence of data exfiltration was found.
California clockDiscovered Aug 5, 2016 → Notified Oct 4, 201660d ✓ CA 60-day OK11 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_030aa96547f5e4daNew Hampshire State AGfiled 2016-10-20Candidate
- bd_0c096a0a3641dc00HHS OCRfiled 2016-10-04(16d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-64474
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 20, 2016
- Raw hash
- 5816591bc815078ccf42590687f086ad5d9a0d5662f9b8fb6eaff10b99e6e7f6
Reporting entity
- Name
- Apria Homenorm: apria home
- Domain
- apriahome.com
Victim entity
- Name
- Apria Healthcare LLCnorm: apria healthcare
- Domain
- apria.com
Incident
- Discovered
- Aug 5, 2016
- Materiality determined
- —
- Notification sent
- Oct 4, 2016
- Affected individuals
- 912
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Providing written notice of this incident to other state regulators where required
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(76 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 60d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 5, 2016→ Notified: Oct 4, 201660d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.