Lincare Holdings Inc.
ent_019e0be5fa430f494ac4634d5a93baa9
Disclosures
21
State AG · Leak Site · HHS OCR · HHS OCR enforcement · 11 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
2,918,444
nationwide · HHS OCR FL
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Lincare Holdings Inc.
- Normalized
- lincare holdings— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300FTP517YSKN0O68
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- lincare.com
- Corporate parent
- Linde plc— per SEC Exhibit 21 filing
Disclosure history (21)newest first
- Illinois State AGas victim2026-06-01
LINCARE INC. filed a data-breach notice with the Illinois Attorney General in June 2026 (case 26-06-1271). The register records the breach as discovered on June 2, 2026. Personal information types reported: medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2025-11-01
LINCARE HOLDINGS, INC filed a data-breach notice with the Illinois Attorney General in November 2025 (case 25-11-600). The register records the breach as discovered on October 7, 2025. Personal information types reported: medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2024-04-29
Lincare Holding Inc. notified Montana residents of a data breach involving MOVEit Transfer software exploited by an unauthorized party. The incident, discovered Dec 21, 2023, involved data extracted on May 31, 2023, including names, addresses, DOBs, and insurance info. Philips Respironics, the vendor, suspended the tool and offered credit monitoring.
- New Hampshire State AGas victim2023-01-09
Lincare Holdings Inc. filed a supplemental notice with the NH AG regarding a 2021 unauthorized network access. First access occurred Sept 10, 2021; detected Sept 26, 2021. Affected ~3,822 NH residents with names, PHI, SSNs. Incident contained Sept 29, 2021. Notifications completed Jan 3, 2023.
- Oregon State AGas victim2023-01-03
Lincare Holdings Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-01-03. The breach occurred during 9/10/2021 - 9/29/2021. The breach was discovered on 9/26/2021. Notice was sent on 2/9/20226/3/20226/21/20228/16/20229/1/20229/15/2022.
- California State AGas victim2023-01-03
Lincare Holdings Inc. experienced unauthorized access to certain systems between September 10 and September 29, 2021. The incident was discovered on September 26, 2021. Affected data includes names and other personal information. Lincare engaged outside cybersecurity experts, notified law enforcement, reset passwords, and is offering one year of complimentary credit monitoring through Kroll.
- GLOBALLeak Siteas victim2022-10-30
- South Carolina State AGas victim2022-07-18
Lincare Holdings Inc. notified individuals of a security incident where unauthorized access occurred between Sept 10-29, 2021. The breach involved personal info, financial data, and health info. Lincare engaged forensic experts, notified law enforcement, reset passwords, and offered 1 year of credit monitoring.
- New Hampshire State AGas victim2022-06-13
Lincare Holdings Inc. filed a supplemental notice with the New Hampshire AG regarding a security incident where unauthorized access occurred between Sept 10-29, 2021. The breach affected NH residents' names, health/financial info, SSNs, and driver's licenses. Lincare engaged forensic experts, reset passwords, and offered credit monitoring.
- Oregon State AGas victim2022-06-06
Lincare Holdings Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2022-06-06. The breach occurred during 9/10/2021 - 9/29/2021. The breach was discovered on 9/26/2021. Notice was sent on 2/9/20226/3/2022.
- California State AGas victim2022-06-06
Lincare Holdings Inc. notified the California AG of a security incident where unauthorized access occurred between September 10 and September 29, 2021. The company identified unusual activity on September 26, 2021. Personal information, including names, was potentially involved. Lincare secured its network, reset passwords, engaged cybersecurity experts, and notified law enforcement. Affected individuals are offered one year of complimentary identity and credit monitoring.
- Oregon State AGas victim2022-04-11
Lincare Holdings Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2022-04-11. The breach occurred during 9/10/2021 - 9/29/2021. The breach was discovered on 9/26/2021.
- Washington State AGas victim2022-03-25
Lincare Holdings Inc. reported unauthorized access to its network affecting 37,050 Washington residents. Access occurred Sept 10-29, 2021; discovered Sept 26, 2021. Data included names, health/insurance info, SSNs, and driver's licenses. Lincare engaged forensic experts, reset passwords, and offered credit monitoring.
- New Hampshire State AGas victim2022-02-23
Lincare Holdings Inc. notified the NH AG of a security incident where unauthorized access occurred between Sept 10-29, 2021. Discovered Sept 26, 2021. Affected 5 NH residents. Data included names, SSNs, financial accounts, and health info. Response included law enforcement notification, password resets, and 1 year of credit monitoring.
- Massachusetts State AGas victim2022-02-15
Lincare Holdings Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-02-15. 22,313 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2022-02-09
Lincare Holdings Inc. disclosed a security incident in Montana where unauthorized access to its network occurred between September 10 and 29, 2021. The breach was discovered on September 26, 2021, and notification letters were sent on December 15, 2021. Personal information, including names and data elements, was potentially exposed. Lincare engaged outside cybersecurity experts, notified law enforcement, reset passwords, and offered one year of complimentary credit monitoring via Kroll.
- Illinois State AGas victim2022-01-01
LINCARE HOLDINGS filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-378). The register records the breach as discovered on February 9, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- California State AGas victim2021-11-24
Lincare Holdings Inc. identified unusual activity on its network on September 26, 2021. Investigation confirmed unauthorized access occurred between September 10 and September 29, 2021. The incident may have involved patient personal information, including PHI. Lincare secured the network, reset passwords, engaged forensic experts, and notified law enforcement. Credit monitoring is being offered to affected individuals.
- FLORIDAHHS OCRas victim2021-10-26
Lincare Holdings Inc. reported to HHS on 2021-10-26 a Hacking/IT Incident affecting 2,918,444 individuals. Breached information located on Network Server. The incident involved PHI including names, addresses, SSNs, and medical/financial data. The entity offered credit monitoring and implemented safeguards.
- Illinois State AGas victim2021-01-01
LINCARE HOLDINGS, INC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-454). The register records the breach as discovered on September 26, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- FEDERALHHS OCR enforcementas victim2016-02-03
HHS Administrative Law Judge ruled that Lincare, Inc. violated the HIPAA Privacy Rule, granting summary judgment to OCR and requiring Lincare to pay $239,800 in civil money penalties.