HomeSecurityHealthEquity breach affects 4.3 million people

HealthEquity breach affects 4.3 million people

HSA provider HealthEquity found that a data breach, disclosed earlier this month, has compromised the information of 4.3 million people .

See also: BMW data breach exposed details of 14,000 customers

HealthEquity breach

HealthEquity, one of the largest HSA custodians in the US, specializes in providing health savings accounts (HSAs), flexible spending accounts (FSAs), health reimbursement arrangements (HRAs) and 401(k) retirement plans.

Recently, the company revealed that malicious actors stole sensitive member health data using compromised credentials from a partner. An investigation found that the breach occurred on March 9, 2024, but was only verified by the company on June 26, after an internal investigation.

We have discovered unauthorized access and potential disclosure of protected health information and/or personal information, stored in an unstructured data repository outside of our core systems,” states the data breach notification that will be sent to affected individuals.

The data that have been exposed as a result of this breach at HealthEquity vary per individual and include:

  • Full names
  • Home address
  • Phone number
  • Employer and employee identity
  • Social Security Number (SSN)
  • General dependent information
  • Payment card details (no numbers)

See also: MediSecure: Data breach affects 12.9 million people

HealthEquity breach affects 4.3 million people

The compromised data repository, which HealthEquity clarified was outside of its core systems, has now been secured by terminating unauthorized sessions and blocking IP addresses associated with the attackers.

The company also implemented a global password reset for the vendor whose account was compromised and later used to access the remote database.

The recipients of the HealthEquity breach notifications will also receive a two-year credit monitoring and identity theft protection service through Equifax, with enrollment instructions in the letters.

Affected individuals are advised to remain vigilant, check their account statements for suspicious activity, and log into their HealthEquity account to confirm that their personal profile and contact information are correct.

At this time, no threat actor has claimed responsibility for the attack on HealthEquity, and the stolen data has not been leaked online.

See also: WazirX: Breach leads to theft of $230 million worth of crypto

A data breach, such as the one at HealthEquity, refers to the improper access, use, or disclosure of personal and sensitive information. This situation can occur through data leaks, hacking , or other malicious attacks, and has serious consequences for individuals and businesses. The consequences can include financial losses, legal liabilities, and loss of trust from customers. It is essential that organizations implement strict security policies and train their employees to minimize the risk of data breaches.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS