Apria Healthcare LLC
ent_f512328864373f5574aded1a
Disclosures
23
HHS OCR · State AG · 11 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
1,869,598
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Apria Healthcare LLC
- Normalized
- apria healthcare— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- apria.com
Disclosure history (23)newest first
- INDIANAHHS OCRas victim2025-03-28
Apria Healthcare LLC (IN) reported to HHS on 2025-03-28 an Unauthorized Access/Disclosure affecting 713 individuals. An employee mailed PHI to wrong recipients; information involved included names, addresses, and unique identification numbers. Breached information was on Paper/Films. No business associate was involved. The CE notified HHS and affected individuals, and implemented additional administrative, technical, and security safeguards.
- New Hampshire State AGas victim2023-05-31
Apria Healthcare LLC notified New Hampshire residents of a security incident where an unauthorized third party accessed systems containing personal information between April 2019 and October 2021. The actor's intent was financial fraud; no evidence of funds removal or data exfiltration was found. 8,566 NH residents were affected. Apria engaged the FBI and forensic investigators, implemented security measures, and offered 12 months of Kroll identity protection services.
- South Carolina State AGas victim2023-05-23
Apria Healthcare, LLC reported unauthorized access to its systems by an unauthorized third party between April 2019 and October 2021. The entity detected the incident on September 1, 2021. The attacker accessed emails and files, potentially to commit fraud. Apria engaged the FBI and forensic investigators, implemented security measures, and offered one year of Kroll identity monitoring to affected individuals.
- Massachusetts State AGas victim2023-05-22
Apria Healthcare LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-05-22. 24,429 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2023-05-22
Apria Healthcare LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2019-04-05 and was reported on 2023-05-22. 42,021 Indiana residents were affected. 1,869,598 individuals affected in total.
- Oregon State AGas victim2023-05-22
Apria Healthcare LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-05-22. The breach occurred during 4/5/2019 - 10/10/2021. The breach was discovered on 9/1/2021. 1,869,598 individuals were affected. Notice was sent on 5/22/2023.
- Delaware State AGas victim2023-05-22
Apria Healthcare, LLC notified Delaware AG of a data breach involving unauthorized third-party access to its systems between April 2019 and October 2021. The attacker's goal was financial fraud, though patient/employee PII (including SSNs and DOBs) was potentially accessed. Apria engaged the FBI and forensic investigators, implemented security measures, and offered one year of Kroll identity monitoring services.
- Maine State AGas victim2023-05-22
Apria Healthcare LLC reported a breach affecting 1,869,598 individuals, including 7,162 Maine residents. The incident occurred between April 4, 2019, and October 10, 2021, and was discovered on October 1, 2021. The breach involved unauthorized external access (hacking) resulting in the acquisition of names, personal identifiers, and financial account numbers. Apria provided 12 months of identity theft protection and credit monitoring via Kroll.
- Montana State AGas victim2023-05-22
Apria Healthcare LLC notified Montana residents of unauthorized access to its systems between April 2019 and October 2021. The attacker sought to fraudulently obtain funds. Apria engaged the FBI and forensic investigators, implemented security measures, and offered one year of Kroll identity monitoring to affected individuals.
- California State AGas victim2023-05-22
Apria Healthcare LLC notified patients and employees of unauthorized access to systems containing personal and health information. The incident involved two periods of access: April 5, 2019 to May 7, 2019, and August 27, 2021 to October 10, 2021. Apria became aware of the breach on September 1, 2021. The attacker's motive was believed to be financial fraud against Apria, not data theft, though no proof of data exfiltration exists. Apria engaged the FBI and forensic investigators, implemented security enhancements, and offered one year of identity monitoring via Kroll.
- Washington State AGas victim2023-05-22
Apria Healthcare LLC notified Washington AG of unauthorized access to systems containing patient data between 2019 and 2021. Discovered Sept 1, 2021. Access was for financial fraud, not PII theft, but PII/PHI potentially accessed. 69,686 WA residents notified. FBI and forensic investigators engaged. Kroll identity monitoring offered.
- Illinois State AGas victim2023-01-01
APRIA HEALTHCARE LLC filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-329). The register records the breach as discovered on April 5, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- INDIANAHHS OCRas victim2022-05-16
Apria Healthcare LLC reported to HHS on 2022-05-16 a Hacking/IT Incident affecting 1,868,831 individuals. Breached information located on Email. An employee was the subject of an email phishing scheme. PHI involved included names, dates of birth, addresses, drivers’ license and social security numbers, claims and financial information, diagnoses, lab results, medications, and other treatment information. The CE implemented additional technical and security safeguards in response to the breach.
- New Hampshire State AGas victim2016-10-20
Apria Healthcare, a provider of home respiratory services, notified the NH AG of a cyber incident affecting 3 NH residents. On Aug 5, 2016, an employee's email account was accessed via unauthorized means (likely phishing). Data exposed included names, DOB, SSN, diagnosis, and medical record numbers. No data exfiltration was found. Notices mailed Oct 4, 2016. Credit monitoring offered.
- California State AGas victim2016-10-20
On August 5, 2016, Apria Healthcare discovered unauthorized access to an employee's email account. The incident potentially exposed personal and medical information, including names, dates of birth, Social Security numbers, and diagnosis information, for 912 California residents. Apria Healthcare engaged forensic experts, changed credentials, and offered 12 months of credit monitoring. No evidence of data exfiltration was found.
- CALIFORNIAHHS OCRas victim2016-10-04
Apria Healthcare (CA, healthcare provider) reported to HHS OCR on 2016-10-04 that a workforce member fell for a phishing scam, granting unauthorized access to her work email account. Approximately 1,987 individuals were potentially affected. PHI involved included names, Social Security numbers, dates of birth, driver's license numbers, medical record numbers, diagnoses, and other clinical information. The CE notified affected individuals, HHS, and the media; provided free credit monitoring; revised policies and procedures; and trained workforce on phishing. OCR provided technical assistance and obtained assurances of corrective actions.
- CALIFORNIAHHS OCRas victim2012-10-10
Apria Healthcare, Inc. reported to HHS OCR on 2012-10-10 a Theft affecting 65,700 individuals. Breached information was located on a Laptop. No business associate was identified as involved in the breach.
- California State AGas victim2012-09-28
Apria Healthcare, Inc. reported a data breach to the California Attorney General. The breach occurred on June 14, 2012. The provided source document contains only the filing metadata and an empty attachment placeholder; no narrative details regarding the nature of the breach, data types affected, or number of individuals impacted are available in the text.
- New Hampshire State AGas victim2012-09-27
Apria Healthcare, Inc. reported the theft of an unencrypted, password-protected laptop from an employee's vehicle on June 14, 2012. The laptop contained protected health information (PHI) and personally identifiable information (PII), including Social Security numbers, names, and potentially dates of birth, for patients. This supplemental notice updates the count of affected New Hampshire residents to 121. The company notified law enforcement, engaged forensic experts, and is offering one year of credit monitoring to affected individuals. Remediation efforts include encrypting all laptops and retraining employees.
- Massachusetts State AGas victim2012-08-23
Apria Healthcare reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-08-23. 342 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2012-08-15
Apria Healthcare, Inc. reported the theft of an unencrypted laptop containing PHI and PII of 5 New Hampshire residents. The laptop was stolen from an employee's vehicle on June 14, 2012. Apria notified law enforcement, HHS, and affected individuals. Remediation included employee retraining and encrypting company laptops.
- California State AGas victim2012-08-15
Apria Healthcare, Inc. reported the theft of a laptop on June 14, 2012. The unencrypted device contained patient personal information, including Social Security numbers, names, and potentially dates of birth and health information. The company offered one year of identity protection services and is working with law enforcement.
- CALIFORNIAHHS OCRas victim2012-08-15
Apria Healthcare, Inc. reported to HHS on 2012-08-15 a Theft affecting 11,000 individuals (HHS-listed count; the web description references 65,700 individuals in the laptop). An unencrypted laptop was stolen from a workforce member's locked vehicle. PHI exposed included names, addresses, birth dates, SSNs, driver's licenses, and financial and medical information. The CE sanctioned the employee, encrypted all laptops and desktops, and retrained staff. OCR obtained assurances of corrective action.