Back to the register

Apria Healthcare

ArchivedSubmitted 10/04/2016
State
CA
Covered entity type
Healthcare Provider
Individuals affected
1,987
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Due to a phishing scam a workforce member provided unauthorized access to her work email account. On August 5, 2016, the covered entity (CE), Apria Healthcare, reported that approximately 1,987 individuals were potentially affected. The protected health information (PHI) involved included patients’ names, social security numbers, dates of birth, drivers’ license numbers, medical record numbers, diagnoses, and other clinical information. The CE provided breach notification to affected individuals, HHS, and the media. The CE also provided free credit monitoring services to the affected individuals. The CE revised its policies and procedures and provided training on phishing scams to all workforce members. OCR provided substantial technical assistance to the CE and obtained assurances that the CE implemented the corrective actions noted above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.