Due to a phishing scam a workforce member provided unauthorized access to her work email account. On August 5, 2016, the covered entity (CE), Apria Healthcare, reported that approximately 1,987 individuals were potentially affected. The protected health information (PHI) involved included patients’ names, social security numbers, dates of birth, drivers’ license numbers, medical record numbers, diagnoses, and other clinical information. The CE provided breach notification to affected individuals, HHS, and the media. The CE also provided free credit monitoring services to the affected individuals. The CE revised its policies and procedures and provided training on phishing scams to all workforce members. OCR provided substantial technical assistance to the CE and obtained assurances that the CE implemented the corrective actions noted above.
2026-09-25 · attack: unknown to insider · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 1987 · backfill source
2026-09-25 · disclosed: 2016-10-20 to 2016-10-04 · backfill source
2026-09-25 · summary: empty to Due to a phishing scam a workforce member provided unauthorized access to her work email account. On August 5, 2016, the covered entity (CE), Apria Healthcare, reported that approximately 1,987 individuals were potentially affected. The pro · backfill source