Apria Healthcare LLC Data Breach
Apria Healthcare Hacking Incident Affects 1.8M Patients
What happened in the Apria Healthcare LLC data breach?
The Apria Healthcare LLC data breach was reported on May 16, 2022 and affected 1,868,831 individuals. The breach type was Hacking/IT Incident involving Email, Network Server. This breach occurred in Indiana. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Apria Healthcare LLC Breach Details
Apria Healthcare Data Breach Report
Breach Overview
Apria Healthcare LLC, a major home healthcare and medical equipment provider based in Indiana, experienced a significant data breach involving unauthorized access to patient information stored on email systems and network servers. The breach was discovered and reported to the U.S. Department of Health and Human Services on May 16, 2022, affecting approximately 1.87 million individuals. This incident represents one of the largest healthcare data breaches reported in 2022 and underscores the ongoing vulnerability of healthcare organizations to sophisticated cyber attacks targeting networked infrastructure.
Discovery and Response Timeline
Apria Healthcare identified unauthorized access to its systems through security monitoring and investigation protocols. Upon discovery, the organization initiated a comprehensive investigation to determine the scope of the breach, identify affected individuals, and assess what personal health information may have been compromised. The company worked to secure its systems and prevent further unauthorized access. In accordance with HIPAA Breach Notification Rule requirements, Apria Healthcare began notifying affected individuals of the breach. The submission to HHS on May 16, 2022, indicates the organization met its obligation to report breaches affecting 500 or more residents of a state or jurisdiction to the media and HHS Secretary.
Technical Details of the Incident
The breach involved unauthorized access to email systems and network servers—critical infrastructure components that typically store and transmit sensitive patient information. Email systems are particularly vulnerable targets because they often contain unencrypted communications with patient details, appointment information, and clinical notes. Network servers may house databases containing consolidated patient records, billing information, and administrative data. Hacking incidents of this nature typically involve sophisticated threat actors using methods such as credential compromise, exploitation of unpatched vulnerabilities, phishing campaigns targeting employees, or brute-force attacks against inadequately secured access points. The fact that both email and network server systems were compromised suggests either a widespread vulnerability in the organization's infrastructure or a determined, multi-stage attack that allowed attackers to move laterally through the network after initial compromise.
Organizational Context
Apria Healthcare LLC is one of the largest home healthcare and durable medical equipment (DME) providers in the United States. The company operates across multiple states, including Indiana where it is headquartered, providing respiratory therapy, infusion therapy, mobility assistance, and other home-based medical services to hundreds of thousands of patients. As a major healthcare service provider, Apria maintains extensive patient databases containing sensitive health information necessary to coordinate care, process insurance claims, and manage patient accounts. The organization's size and scope of operations—serving patients across numerous states—meant that a breach of its central systems would have far-reaching consequences affecting patients in multiple jurisdictions.
Impact on Affected Individuals
Approximately 1,868,831 individuals were affected by this breach, making it a breach of national significance. Patients whose information was stored on the compromised email and network server systems may have had their personal health information exposed to unauthorized parties. The specific data elements exposed likely included names, addresses, dates of birth, Social Security numbers, insurance information, medical record numbers, and clinical information related to their home healthcare services. Some patients may have had financial information, banking details, or other sensitive identifiers exposed depending on what data was maintained in the affected systems. Notification of affected individuals occurred following the discovery and investigation of the breach, with Apria Healthcare providing guidance on protective measures and credit monitoring services where appropriate.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, covered entities and business associates must notify affected individuals, the media, and the HHS Secretary when a breach of unsecured protected health information affects 500 or more residents of a state or jurisdiction. Apria Healthcare's notification to HHS reflects compliance with these requirements. This incident is consistent with broader trends in healthcare cybersecurity: hacking and IT incidents represent the leading cause of healthcare data breaches by volume, accounting for the majority of breaches affecting large numbers of individuals. The healthcare sector remains a prime target for cyber criminals due to the high value of health information on the dark web, the critical nature of healthcare systems that may incentivize payment of ransoms, and sometimes inadequate cybersecurity investments relative to clinical priorities. Organizations like Apria Healthcare, which operate complex networked environments serving large patient populations, face particular challenges in securing all access points and maintaining strong defenses against evolving threats.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Apria Healthcare LLC Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
Review explanation of benefits (EOB) statements and insurance claims carefully for any services or charges you did not authorize. Contact your insurance provider immediately if you identify fraudulent claims or unauthorized medical services.
Change passwords for any online healthcare portals, insurance accounts, and email accounts, using strong, unique passwords. Enable multi-factor authentication where available to prevent unauthorized account access.
Consider enrolling in credit monitoring and identity theft protection services if offered by Apria Healthcare or your insurance provider. These services can provide early detection of fraudulent activity and assistance with remediation if identity theft occurs.
Be cautious of unsolicited communications claiming to be from healthcare providers, insurance companies, or financial institutions. Verify any requests for personal information by contacting organizations directly using phone numbers or websites you know to be legitimate, rather than using contact information provided in suspicious communications.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Indiana Breaches
Search all breaches reported in Indiana
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits