Apria Class Action Lawsuit: Data Breach Settlement and Payouts

The Apria class action lawsuit was a consolidated data breach case against Apria Healthcare LLC that ended in a $6.375 million non-reversionary settlement approved by a federal judge in Indiana on November 17, 2025. The case covered roughly 1.87 million people whose personal, financial, and medical information was exposed in two separate cyberattacks in 2019 and 2021. The claims deadline has passed and the case has been dismissed with prejudice.1GovInfo. Smith et al. v. Apria Healthcare LLC, Final Class Settlement Approval Order

What Data Was Exposed

Two separate intrusions gave unauthorized third parties access to Apria’s systems. The first ran from April 5 to May 7, 2019. The second ran from August 27 to October 10, 2021. Attackers reached millions of internal documents and several employee email accounts, including the CEO’s.2Indiana Governor’s Office. Attorney General Todd Rokita Continues Fight for Patient Privacy, Files Suit Against Apria Healthcare

The exposed information included Social Security numbers, birth certificates, credit and debit card details, medical histories, addresses, and health insurance information.2Indiana Governor’s Office. Attorney General Todd Rokita Continues Fight for Patient Privacy, Files Suit Against Apria Healthcare About 1.87 million people nationwide were affected. The FBI notified Apria of the intrusion on September 1, 2021, but breach notices did not reach patients until May 2023, roughly 20 months later.3HIPAA Journal. Apria Healthcare Breach Affects Up to 1.8 Million Individuals That delay drove much of the litigation that followed.

The consolidated complaint, filed in the Southern District of Indiana in October 2023, alleged negligence, breach of contract, breach of fiduciary duty, unjust enrichment, invasion of privacy, and violations of consumer protection laws in Indiana, California, Illinois, Washington, Missouri, and New York. Apria denied wrongdoing and settled to avoid the cost and uncertainty of continued litigation.4HIPAA Journal. Apria Healthcare Data Breach Settlement

What the Settlement Paid

Apria funded a $6,375,000 settlement pool with no money reverting to the company. The settlement class included anyone who received notice from Apria that their information may have been compromised in the 2019 or 2021 hacking events.5Apria Settlement. Apria Settlement Homepage

Class members who filed valid claims could receive two kinds of payments. The first was reimbursement of up to $2,000 per person for documented out-of-pocket losses traceable to the breaches, such as unreimbursed fraud losses, credit monitoring, credit repair or legal fees, and smaller expenses like postage and notary fees.6Apria Settlement. Frequently Asked Questions The second was a pro rata cash payment split among all approved claimants from whatever remained in the fund after fees, costs, service awards, and out-of-pocket reimbursements were paid.7ClassAction.org. $6.375M Apria Healthcare Settlement Aims to Resolve Data Breach Lawsuit

The court approved $1,699,212.44 in attorneys’ fees, $1,211,210.08 in notice and administration costs, $39,897.57 in litigation costs, and $63,000 in service awards, split as $3,000 to each of 21 class representatives.1GovInfo. Smith et al. v. Apria Healthcare LLC, Final Class Settlement Approval Order

Final Approval and Claims Status

Judge James Patrick Hanlon held the fairness hearing on November 4, 2025, and issued final approval on November 17, 2025. No class member objected. A total of 42,378 claims were filed and 26 people opted out.1GovInfo. Smith et al. v. Apria Healthcare LLC, Final Class Settlement Approval Order

The deadline to submit an out-of-pocket reimbursement claim was 90 days after the November 17, 2025, final order. Kroll Settlement Administration LLC handled the claims process at (833) 890-6558 and through apriasettlement.com.6Apria Settlement. Frequently Asked Questions

Security Changes Apria Had to Make

Money was not the only piece of the deal. Apria also agreed, at its own expense, to strengthen its cybersecurity through enhanced employee training, stronger data security policies, tighter access restrictions on personal information, and upgraded monitoring and response capabilities.8ClassAction.org. In Re Apria Data Breach Litigation Memorandum

The Indiana Attorney General’s Separate Case

The class action did not resolve every claim against Apria over these breaches. Indiana Attorney General Todd Rokita filed a separate civil lawsuit on February 29, 2024, alleging violations of HIPAA’s notification, security, and privacy rules, Indiana’s Disclosure of Security Breach Act, and the Indiana Deceptive Consumer Sales Act. The state’s complaint focused on the 629-day notification delay and alleged that Owens & Minor knew about the breaches when it acquired Apria in March 2022. That case was still unresolved as of the most recent available reporting and is not part of the class action settlement.4HIPAA Journal. Apria Healthcare Data Breach Settlement