Aveanna Healthcare LLC
ent_019e10dc00c9462c2a5c3384a49c7207
Disclosures
10
HHS OCR · State AG · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
166,077
nationwide · HHS OCR GA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Aveanna Healthcare LLC
- Normalized
- aveanna healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493006D6JRLPIY8YV18
- SEC EDGAR CIK
- 0001832332
- Domain
- aveanna.com
Disclosure history (10)newest first
- GEORGIAHHS OCRas victim2024-07-12
Aveanna Healthcare, LLC reported to HHS on 2024-07-12 a Unauthorized Access/Disclosure affecting 10,482 individuals. Breached information located on Email. Multiple employees emailed PHI including names, DOB, SSNs, diagnoses, and insurance info to personal accounts. CE provided credit monitoring and strengthened safeguards.
- Montana State AGas victim2024-03-15
Aveanna Healthcare notified Montana residents of a data security incident. On September 22, 2023, the company detected unusual activity on an email account. Investigation revealed an unknown actor gained unauthorized access on September 25, 2023, potentially accessing files containing personal and health information. Notifications were sent to affected individuals offering medical identity protection services.
- GEORGIAHHS OCRas victim2024-03-15
Aveanna Healthcare (GA) reported to HHS on 2024-03-15 a Hacking/IT Incident affecting 65,482 individuals. An employee was the subject of an email phishing scheme that compromised PHI including names, Social Security and driver's license numbers, dates of birth, diagnoses, health insurance information, prescription information, and claims information. Breached information was located in Email. The CE sanctioned the employee, offered credit monitoring, and implemented additional administrative and technical safeguards.
- GEORGIAHHS OCRas victim2020-02-14
Aveanna Healthcare (GA) reported to HHS on 2020-02-14 a Hacking/IT Incident affecting 166,077 individuals via an email phishing attack. Compromised ePHI included names, dates of birth, driver's license numbers, addresses, phone numbers, SSNs, clinical information, financial information, and health insurance information. Breached information located in Email. The CE notified HHS, affected individuals, and the media, implemented additional technical safeguards, and retrained staff. OCR provided technical assistance and obtained corrective-action assurances.
- Massachusetts State AGas victim2020-02-14
Aveanna Healthcare reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-02-14. 4,084 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2020-02-14
Aveanna Healthcare experienced unauthorized access to employee email accounts between July 9, 2019, and August 24, 2019. The incident was discovered on August 24, 2019. Personal information, including SSNs, driver's licenses, financial account info, and medical/health insurance data, for 5,004 California residents was potentially exposed. Aveanna engaged forensic specialists, secured accounts, implemented MFA, and offered 12 months of credit monitoring.
- Washington State AGas victim2020-02-14
Aveanna Healthcare reported a cybersecurity incident affecting 2,444 Washington residents. Unauthorized access to employee email accounts occurred between July 9, 2019, and August 24, 2019. Compromised data included SSNs, driver's licenses, and financial account numbers. Aveanna engaged forensic specialists, reset credentials, implemented MFA, and offered 12 months of credit monitoring.
- Montana State AGas victim2020-02-14
Aveanna Healthcare disclosed that an unknown actor accessed employee email accounts between July 9 and August 24, 2019, likely via phishing. The incident involved personal information (PII) and protected health information (PHI) of patients and employees. Aveanna secured accounts, engaged forensic specialists, implemented MFA, and offered credit monitoring.
- Illinois State AGas victim2020-01-01
AVEANNA HEALTHCARE filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-060). The register records the breach as discovered on August 14, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2019-06-06
Aveanna Healthcare reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-06-06. 1 Massachusetts residents were affected. The report records the breach type as paper.
Subsidiary disclosures (3)filed by group companies
◈ These filings were made by or about subsidiaries of Aveanna Healthcare LLC — not by Aveanna Healthcare LLC itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Indiana State AGvia Loving Care Agency, Inc2023-07-31
Loving Care Agency, Inc DBA Aveanna Healthcare reported a data breach to the Indiana Attorney General. The breach occurred on 2023-07-25 and was reported on 2023-07-31. 94 Indiana residents were affected.
- Massachusetts State AGvia American Staffing Association2020-08-01
American Staffing Association reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-08-01. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGvia American Staffing Association2020-07-29
American Staffing Association reported a data breach to the Indiana Attorney General. The breach occurred on 2020-04-13 and was reported on 2020-07-29. 2 Indiana residents were affected. 18 individuals affected in total.