HealthEquity Details
Industry
Healthcare
Security Incidents
1
HealthEquity, Inc. is a leading provider of health savings accounts (HSAs) and other consumer-directed benefits like health reimbursement arrangements (HRAs) and flexible spending accounts (FSAs). Founded in 2002, the company focuses on empowering consumers to save for their healthcare needs and maximize their healthcare dollars through tax-advantaged savings accounts. HealthEquity has developed a comprehensive platform for managing these accounts, providing users with tools and resources to make informed decisions about their healthcare spending and investments.
In addition to HSAs, HRAs, an...
Show more
Security Incidents
HealthEquity Breach of Jul 2024
Show more
Show more
Show more
Severity Score
Significant
Type
3rd Party CompromiseSummary
HealthEquity experienced a data breach after a partner's account was compromised, leading to unauthorized access to its systems and the exfiltration of protected health information (PHI). The breach was discovered when HealthEquity detected unusual behavior from a partner’s personal device, prompting an internal investigation. The investigation determined that the partner’s account had been hijacked by hackers, who accessed and transferred sensitive data, including personally identifiable information (PII) and PHI. HealthEquity, which manages millions of health savings accounts (HSAs) and othe...Show more
Severity
HealthEquity, a major healthcare fintech firm, experienced a data breach when a partner's compromised account was used to access its systems and exfiltrate protected health and personally identifiable information. While there is no evidence of malware deployment or disruption to business operations, the breach affects an unspecified number of members, prompting HealthEquity to offer credit monitoring and identity restoration services. Given the breach's nature, impact on sensitive health data, and potential long-term repercussions for the affected individuals, this incident is rated a "Signifi...Show more
Impact
HealthEquity recently experienced a data breach due to a compromised partner's account, leading to unauthorized access to their systems. The breach resulted in the exfiltration of protected health information and personally identifiable information of certain members. Despite this, HealthEquity's investigation confirmed no malware was introduced to their systems, and business operations continued without interruption. While the exact number of affected individuals remains undisclosed, the company has initiated notifications and is providing complimentary credit monitoring and identity restorat...Show more
Other incidents caused by this HealthEquity incident
KEEP YOUR ENVIRONMENT SECURE
Weak credentials are the leading cause of breaches. Beyond Identity can help.
See MFA exploits in action
Watch how adversaries exploit companies in quick videos