Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

4.3 Million Impacted by HealthEquity Data Breach

HealthEquity says the personal and health information of 4.3 million individuals was compromised in a data breach.

HealthEquity is notifying 4.3 million individuals that their personal and health information was compromised in a data breach at a third-party vendor.

The incident, the company said in a regulatory filing with the Maine Attorney General’s Office, was identified on March 25 and required an “extensive technical investigation”.

“Through this work, we discovered some unauthorized access to and potential disclosure of protected health information and/or personally identifiable information stored in an unstructured data repository outside our core systems,” HealthEquity said.

According to the company, the data was exposed after attackers compromised a vendor’s user accounts that had access to the online repository, gaining access to the information stored there.

“We took immediate actions including disabling all potentially compromised vendor accounts and terminating all active sessions; blocking all IP addresses associated with threat actor activity; and implementing a global password reset for the impacted vendor,” the company said.

Depending on the individual, the impacted personally identifiable information (PII) and protected health information (PHI) may include name, address, phone number, Social Security number, employee ID, employer, dependent information, and payment card information.

Advertisement. Scroll to continue reading.

HealthEquity also said that the compromised data mainly included sign-up information for the accounts and benefits it administers.

The company did not name the compromised vendor, but told the Maine AGO that it will mail notification letters to roughly 4.3 million people starting August 9.

HealthEquity is providing the impacted individuals with two years of free credit identity monitoring, insurance, and restoration services and is encouraging them to monitor their accounts for suspicious activity.

“We are not aware of any actual or attempted misuse of information because of this incident to date,” the company said.

Related: 57,000 Patients Impacted by Michigan Medicine Data Breach

Related: MediSecure Data Breach Impacts 12.9 Million Individuals

Related: MarineMax Notifying 123,000 of Data Breach Following Ransomware Attack

Related: MNGI Digestive Health Data Breach Impacts 765,000 Individuals

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

Patrick McKinney has joined Turing as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.