HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTFINANCIAL_ACCOUNTMediumContained
HEALTHEQUITY, INC.
bd_055f9b1868e64ea8 · schema v1 · pii pii-v1
Full breach record for HEALTHEQUITY, INC. →HealthEquity, Inc. reported a data security incident where a vendor's user accounts were compromised, leading to unauthorized access to personally identifiable information and protected health information. The breach occurred on March 9, 2024, and was discovered on March 25, 2024. Affected data includes names, addresses, SSNs, and payment card info. HealthEquity engaged third-party experts, disabled compromised accounts, and offered two years of credit monitoring.
California clockDiscovered Mar 25, 2024 → Notified Jun 26, 202493d ✗ CA 60-day late13 months discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_e37a99ced8da956cNew Hampshire State AGfiled 2025-03-24(16d gap)Verified
- bd_48a6e8a9a9e850d7California State AGfiled 2025-03-21(19d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-601166
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 9, 2025
- Raw hash
- 16c89e422b9d4affd3138edee3c5a3d0cd3e0fc95d71268141866cc33d07d744
Reporting entity
- Name
- HEALTHEQUITY, INC.norm: healthequity
- Domain
- healthequity.com
Victim entity
- Name
- HEALTHEQUITY, INC.norm: healthequity
- Domain
- healthequity.com
Incident
- Discovered
- Mar 25, 2024
- Materiality determined
- —
- Notification sent
- Jun 26, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 13 months(380 days from discovery to filing)
- Compliance flags
- CA 60-day late · 93dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 25, 2024→ Notified: Jun 26, 202493d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.