Apria Healthcare LLC
ent_f512328864373f5574aded1a
Disclosures
17
HHS OCR · State AG · 8 jurisdictions
Incidents
4
filings grouped by incident
Max affected reported
1,869,598
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Apria Healthcare LLC
- Normalized
- apria healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- apria.com
Disclosure history (17)newest first
- INDIANAHHS OCRas victim2025-03-28
Apria Healthcare LLC (IN) reported to HHS on 2025-03-28 an Unauthorized Access/Disclosure affecting 713 individuals. An employee mailed PHI to wrong recipients; information involved included names, addresses, and unique identification numbers. Breached information was on Paper/Films. No business associate was involved. The CE notified HHS and affected individuals, and implemented additional administrative, technical, and security safeguards.
- ⛰️New Hampshire State AGas victim2023-05-31
Apria Healthcare LLC notified New Hampshire residents of a security incident where an unauthorized third party accessed systems containing personal information between April 2019 and October 2021. The actor's intent was financial fraud; no evidence of funds removal or data exfiltration was found. 8,566 NH residents were affected. Apria engaged the FBI and forensic investigators, implemented security measures, and offered 12 months of Kroll identity protection services.
- 🦫Oregon State AGas victim2023-05-22
Apria Healthcare LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-05-22. The breach occurred during 4/5/2019 - 10/10/2021. The breach was discovered on 9/1/2021. 1,869,598 individuals were affected. Notice was sent on 5/22/2023.
- 💎Delaware State AGas victim2023-05-22
Apria Healthcare, LLC notified Delaware AG of a data breach involving unauthorized third-party access to its systems between April 2019 and October 2021. The attacker's goal was financial fraud, though patient/employee PII (including SSNs and DOBs) was potentially accessed. Apria engaged the FBI and forensic investigators, implemented security measures, and offered one year of Kroll identity monitoring services.
- 🦞Maine State AGas victim2023-05-22
Apria Healthcare LLC reported a breach affecting 1,869,598 individuals, including 7,162 Maine residents. The incident occurred between April 4, 2019, and October 10, 2021, and was discovered on October 1, 2021. The breach involved unauthorized external access (hacking) resulting in the acquisition of names, personal identifiers, and financial account numbers. Apria provided 12 months of identity theft protection and credit monitoring via Kroll.
- 💎Delaware State AGas victim2023-05-22
Apria Healthcare LLC notified Delaware AG of unauthorized access to systems between April 2019 and October 2021. The attacker, motivated by financial gain, accessed systems containing patient/employee PII and credentials. Apria engaged the FBI and forensic investigators, implemented security measures, and offered one year of Kroll identity monitoring. No funds were stolen, and no proof of data exfiltration exists, though emails/files may have been accessed.
- 🦬Montana State AGas victim2023-05-22
Apria Healthcare LLC reported a data breach to the Montana Attorney General. The breach was reported on 2023-05-22. The breach occurred from 8/27/2021 to 10/10/2021. 5 Montana residents were affected.
- 🐻California State AGas victim2023-05-22
Apria Healthcare LLC notified patients and employees of unauthorized access to systems containing personal and health information. The incident involved two periods of access: April 5, 2019 to May 7, 2019, and August 27, 2021 to October 10, 2021. Apria became aware of the breach on September 1, 2021. The attacker's motive was believed to be financial fraud against Apria, not data theft, though no proof of data exfiltration exists. Apria engaged the FBI and forensic investigators, implemented security enhancements, and offered one year of identity monitoring via Kroll.
- 🌲Washington State AGas victim2023-05-22
Apria Healthcare LLC, a health sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2021-09-01 and filed notice on 2023-05-22. 69,686 Washington residents were affected. 628 days elapsed between awareness and notification. 880 days to identify the breach. 39 days to contain the breach.
- INDIANAHHS OCRas victim2022-05-16
Apria Healthcare LLC reported to HHS on 2022-05-16 a Hacking/IT Incident affecting 1,868,831 individuals. Breached information located on Email. An employee was the subject of an email phishing scheme. PHI involved included names, dates of birth, addresses, drivers’ license and social security numbers, claims and financial information, diagnoses, lab results, medications, and other treatment information. The CE implemented additional technical and security safeguards in response to the breach.
- ⛰️New Hampshire State AGas victim2016-10-20
Apria Healthcare, Inc. filed a security breach notification with the New Hampshire Attorney General on October 20, 2016. The filing concerns unauthorized access to computerized systems containing personal information and protected health information (PHI) of New Hampshire residents. The specific details regarding the number of affected individuals, the date of discovery, and the method of unauthorized access are not provided in the available document text.
- 🐻California State AGas victim2016-10-20
On August 5, 2016, Apria Healthcare discovered unauthorized access to an employee's email account. The incident potentially exposed personal and medical information, including names, dates of birth, Social Security numbers, and diagnosis information, for 912 California residents. Apria Healthcare engaged forensic experts, changed credentials, and offered 12 months of credit monitoring. No evidence of data exfiltration was found.
- CALIFORNIAHHS OCRas victim2016-10-04
Apria Healthcare (CA, healthcare provider) reported to HHS OCR on 2016-10-04 that a workforce member fell for a phishing scam, granting unauthorized access to her work email account. Approximately 1,987 individuals were potentially affected. PHI involved included names, Social Security numbers, dates of birth, driver's license numbers, medical record numbers, diagnoses, and other clinical information. The CE notified affected individuals, HHS, and the media; provided free credit monitoring; revised policies and procedures; and trained workforce on phishing. OCR provided technical assistance and obtained assurances of corrective actions.
- CALIFORNIAHHS OCRas victim2012-10-10
Apria Healthcare, Inc. reported to HHS OCR on 2012-10-10 a Theft affecting 65,700 individuals. Breached information was located on a Laptop. No business associate was identified as involved in the breach.
- 🐻California State AGas victim2012-09-28
Apria Healthcare, Inc. reported a data breach to the California Attorney General. The breach occurred on June 14, 2012. The provided source document contains only the filing metadata and an empty attachment placeholder; no narrative details regarding the nature of the breach, data types affected, or number of individuals impacted are available in the text.
- 🐻California State AGas victim2012-08-15
Apria Healthcare, Inc. reported the theft of a laptop on June 14, 2012. The unencrypted device contained patient personal information, including Social Security numbers, names, and potentially dates of birth and health information. The company offered one year of identity protection services and is working with law enforcement.
- CALIFORNIAHHS OCRas victim2012-08-15
Apria Healthcare, Inc. reported to HHS on 2012-08-15 a Theft affecting 11,000 individuals (HHS-listed count; the web description references 65,700 individuals in the laptop). An unencrypted laptop was stolen from a workforce member's locked vehicle. PHI exposed included names, addresses, birth dates, SSNs, driver's licenses, and financial and medical information. The CE sanctioned the employee, encrypted all laptops and desktops, and retrained staff. OCR obtained assurances of corrective action.