The covered entity (CE), Apria Healthcare, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 1,868,831 individuals. The PHI involved included names, dates of birth, addresses, drivers’ license and social security numbers, claims and financial information, diagnoses, lab results, medications, and other treatment information. The CE implemented additional technical and security safeguards in response to the breach. OCR provided the CE with technical assistance.
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · disclosed: 2023-05-22 to 2022-05-16 · backfill source
2026-09-25 · summary: empty to The covered entity (CE), Apria Healthcare, reported that an employee was the subject of an email phishing scheme that affected the protected health information (PHI) of 1,868,831 individuals. The PHI involved included names, dates of birth, · backfill source
2026-09-25 · records_basis: empty to organization · backfill source
2026-09-25 · records: empty to 1869598 · backfill source
2026-09-25 · attack: unknown to hacking · backfill source
2026-09-25 · discovered: empty to 2021-09-01 · backfill source