HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICPHIHEALTH_BASICLowContained
Apria Healthcare LLC
bd_ca14fb87d20497f2 · schema v1 · pii pii-v1
Full breach record for Apria Healthcare LLC →Apria Healthcare LLC notified patients and employees of unauthorized access to systems containing personal and health information. The incident involved two periods of access: April 5, 2019 to May 7, 2019, and August 27, 2021 to October 10, 2021. Apria became aware of the breach on September 1, 2021. The attacker's motive was believed to be financial fraud against Apria, not data theft, though no proof of data exfiltration exists. Apria engaged the FBI and forensic investigators, implemented security enhancements, and offered one year of identity monitoring via Kroll.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_484942091b9acd62Oregon State AGfiled 2023-05-22Candidate
- bd_a0195e3f90a18f77Delaware State AGfiled 2023-05-22Verified
- bd_a2be55087df28190Maine State AGfiled 2023-05-22Verified
- bd_b9bdb6b76ef4907eDelaware State AGfiled 2023-05-22Verified
Show 3 more filings ↓Show fewer ↑up to 9d gap
- bd_c1a512d17d99444fMontana State AGfiled 2023-05-22Verified
- bd_e12921387568e40fWashington State AGfiled 2023-05-22Verified
- bd_95d978c59636df32New Hampshire State AGfiled 2023-05-31(9d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-567100
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 22, 2023
- Raw hash
- 9f465ea25f3e7dcded2c92abf086890d1c10bdab732f23e6eb66d05465b47867
Reporting entity
- Name
- Apria Homenorm: apria home
- Domain
- apriahome.com
Victim entity
- Name
- Apria Healthcare LLCnorm: apria healthcare
- Domain
- apria.com
Incident
- Discovered
- Sep 1, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Worked with the Federal Bureau of Investigation (FBI)
Compliance
- Time to disclose
- 21 months(628 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.