Apria Healthcare (CA, healthcare provider) reported to HHS OCR on 2016-10-04 that a workforce member fell for a phishing scam, granting unauthorized access to her work email account. Approximately 1,987 individuals were potentially affected. PHI involved included names, Social Security numbers, dates of birth, driver's license numbers, medical record numbers, diagnoses, and other clinical information. The CE notified affected individuals, HHS, and the media; provided free credit monitoring; revised policies and procedures; and trained workforce on phishing. OCR provided technical assistance and obtained assurances of corrective actions.
Affected (this filing):