American home healthcare equipment provider Apria Healthcare said it suffered a cyber security incident that affected nearly two million people.
Apria said in a recent security incident notification that on September 1, 2021, it identified unauthorised access to its internal network. The company immediately launched an investigation with assistance from cyber security experts to understand the nature and scope of the incident and resolve the issue.
“An unauthorised third party accessed systems which contained personal information from April 5, 2019, to May 7, 2019, and from August 27, 2021 to October 10, 2021.
“Based on its investigation and discussions with law enforcement, Apria believes the purpose of the unauthorised access was to fraudulently obtain funds from Apria and not to access the personal information of its patients or employees. There is no evidence of funds removed, and Apria is not aware of the misuse of personal information related to this incident,” the company
said.
Apria has, however, confirmed that “a small number of emails and files were confirmed to have been accessed, but there is no proof that any data was taken from any system.” The possibility of the threat actor stealing data records cannot however be ruled out.
Apria said the security incident compromised customers’ information such as their names and other personal identifiers, health insurance details, financial information including account numbers, credit and debit card numbers in combination with security codes, access codes, passwords or PINs for accounts and social security numbers.
According to a
filing with the Office of the Maine Attorney General, at least 1,869,598 individuals have been affected by the cyber attack.
The company said it worked with the FBI and conducted a thorough review of the potentially affected systems. It has also implemented additional security measures to help prevent the reoccurrence of a similar incident in the future.
Apria is offering 12 months of complimentary identity and credit monitoring service via Kroll to all affected individuals.