Back to the register

Inogen, Inc.

ArchivedSubmitted 04/17/2018
State
CA
Covered entity type
Healthcare Provider
Individuals affected
29,528
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On April 17, 2018, Inogen, Inc., the covered entity (CE), reported that an unauthorized individual hacked data from its systems by gaining access to an email account belonging to an employee and setting up forwarding of email messages to an unknown, external email address from January 2, 2018 until March 14, 2018. The breach affected approximately 29,000 individuals and the types of protected health information (PHI) compromised included names, addresses, telephone numbers, dates of birth, dates of death, Medicare identification numbers, insurance policy information, and medical equipment provided. The CE provided breach notification to affected individuals, the media, and HHS. As a result of this incident, the CE strengthened its security controls, such as disabling the ability of email users to set forwarding rules, requiring all email users and administrators to change their passwords, and implementing dual-factor authentication for remote email access. OCR obtained assurances that the CE implemented the corrective action steps noted above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.