Confirmed breach. Intrusion Jun 14, 2012, discovered Jun 14, 2012 — the first regulatory filing landed 62 days later (flagged late). 11,000 individuals reported across the linked filings.
Apria Healthcare, Inc. reported the theft of a laptop on June 14, 2012. The unencrypted device contained patient personal information, including Social Security numbers, names, and potentially dates of birth and health information. The company offered one year of identity protection services and is working with law enforcement.
CA 60-day late · 63d
🐻CALIFORNIAHHS OCRMost recentlinked via same-victim cross-source · 100%
Apria Healthcare, Inc. reported to HHS on 2012-08-15 a Theft affecting 11,000 individuals (HHS-listed count; the web description references 65,700 individuals in the laptop). An unencrypted laptop was stolen from a workforce member's locked vehicle. PHI exposed included names, addresses, birth dates, SSNs, driver's licenses, and financial and medical information. The CE sanctioned the employee, encrypted all laptops and desktops, and retrained staff. OCR obtained assurances of corrective action.
Affected (this filing): 11,000
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.