HealthEquity breach traced to a compromised business partner account
- Organization
- HealthEquity, Inc.
- Exploit
- Credential Compromise
- Industry
- Health Benefits Administration
HealthEquity, a United States administrator of health savings accounts and other consumer-directed benefits, disclosed a data breach in a Form 8-K filed with the Securities and Exchange Commission on 2 July 2024. The company said its investigation began after it detected anomalous behaviour associated with a business partner's personal device.
The inquiry found that an unauthorized third party had compromised the partner's user account and used it to access information held in an unstructured data repository outside HealthEquity's core systems. Data was viewed and then transferred off partner systems. HealthEquity said no malicious code had been placed on its own infrastructure.
The affected records covered sign-up and account information for the benefits HealthEquity administers. Reported categories included names, addresses, telephone numbers, employee identification numbers, employer names, Social Security numbers, dependent details and limited payment card information. Full card numbers were not among the fields described.
HealthEquity said it had secured the repository by terminating unauthorized sessions and blocking the addresses used, strengthened controls around the partner account and acted on recommendations from an incident response firm. It began notifying partners, clients and affected members, offering complimentary credit monitoring and identity restoration, and said it held adequate cybersecurity insurance and would seek recourse from the partner. No victim count accompanied the July filing. By the end of the month the company had put the figure at roughly 4.3 million people, dating first access to March 2024 and confirmation of the exposure to 26 June.