Apria Healthcare disclosed 2019 and 2021 breaches affecting 1.87 million people
- Organization
- Apria Healthcare
- Exploit
- Hacking
- Industry
- Healthcare
Apria Healthcare, a United States home medical equipment and respiratory care provider, began mailing breach notification letters in late May 2023 covering two intrusions that had occurred years earlier. The notifications went to approximately 1,869,598 patients and employees.
Forensic work determined that an unauthorized party had access to Apria systems from April 5 to May 7, 2019, and again from August 27 to October 10, 2021. Apria said it was alerted to unauthorized access on September 1, 2021, meaning roughly 20 months elapsed between discovery and notification. The company offered no direct explanation for the delay beyond a statement that the investigation into what data may have been affected had only recently been completed.
The files potentially accessed contained personal and protected health information, including names, medical and health insurance details and, for a limited number of individuals, Social Security numbers, bank account and payment card numbers, security codes, access codes, passwords and account PINs.
Apria told recipients it believed the intruder's purpose was to fraudulently obtain funds from the company rather than to access patient or employee data, and said it found no evidence funds were removed or that files were stolen, while acknowledging that data theft could not be ruled out. It offered a year of complimentary credit monitoring through Kroll and said it had added security measures. Tom Kellermann, senior vice president of cyber strategy at Contrast Security, told The Register that access of that length pointed to backdoors planted in the network and often resold, so Apria could not rule out that patient data had been leaked.