- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 29,528
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On April 17, 2018, Inogen, Inc., the covered entity (CE), reported that an unauthorized individual hacked data from its systems by gaining access to an email account belonging to an employee and setting up forwarding of email messages to an unknown, external email address from January 2, 2018 until March 14, 2018. The breach affected approximately 29,000 individuals and the types of protected health information (PHI) compromised included names, addresses, telephone numbers, dates of birth, dates of death, Medicare identification numbers, insurance policy information, and medical equipment provided. The CE provided breach notification to affected individuals, the media, and HHS. As a result of this incident, the CE strengthened its security controls, such as disabling the ability of email users to set forwarding rules, requiring all email users and administrators to change their passwords, and implementing dual-factor authentication for remote email access. OCR obtained assurances that the CE implemented the corrective action steps noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.