Skip to content

Inogen

Disclosed Apr 13, 20188 years ago29,528 affectedConfirmed

Official notice

On April 17, 2018, Inogen, Inc., the covered entity (CE), reported that an unauthorized individual hacked data from its systems by gaining access to an email account belonging to an employee and setting up forwarding of email messages to an unknown, external email address from January 2, 2018 until March 14, 2018. The breach affected approximately 29,000 individuals and the types of protected health information (PHI) compromised included names, addresses, telephone numbers, dates of birth, dates of death, Medicare identification numbers, insurance policy information, and medical equipment provided. The CE provided breach notification to affected individuals, the media, and HHS. As a result of this incident, the CE strengthened its security controls, such as disabling the ability of email users to set forwarding rules, requiring all email users and administrators to change their passwords, and implementing dual-factor authentication for remote email access. OCR obtained assurances that the CE implemented the corrective action steps noted above.

What is known

People affected29,528 (as reported by the organization)
DisclosedApr 13, 2018
DiscoveredMar 14, 2018
HappenedDec 9, 2017
AttackHacking
Data exposedNames, Health, Emails, Phone numbers, Addresses
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Inogenoag.ca.gov · Official notice
Washington Attorney General breach notice: Inogenatg.wa.gov · Official notice
Oregon DOJ breach notice: Inogenjustice.oregon.gov · Official notice
Indiana Attorney General 2018 data breach report: Inogenin.gov · Official notice
Maine Attorney General breach notice archive: Inogenmaine.gov · Official notice
HHS OCR breach report (archive, resolved): Inogen (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAApr 13, 2018
Washington AGresidents of WAApr 13, 2018518
Oregon DOJresidents of ORApr 13, 201829,528
Indiana AGresidents of INApr 13, 2018843
Maine AGresidents of MEApr 13, 201884
HHS archivetotalApr 17, 201829,528
History of this record
  • 2026-09-25 · summary: empty to On April 17, 2018, Inogen, Inc., the covered entity (CE), reported that an unauthorized individual hacked data from its systems by gaining access to an email account belonging to an employee and setting up forwarding of email messages to an · backfill source
  • 2026-09-25 · data_types: [] to ["names","health","emails","phone","addresses"] · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 29528 · backfill source
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · discovered: empty to 2018-03-14 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Inogen

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.