HEALTHEQUITY, INC.
bd_48a6e8a9a9e850d7 · schema v1 · pii pii-v1
Full breach record for HEALTHEQUITY, INC. →HealthEquity, Inc. reported a data breach affecting HSA/FSA customers. On March 25, 2024, the company detected a systems anomaly. Investigation revealed that a third-party vendor's user accounts were compromised, allowing unauthorized access to an online data storage location containing personally identifiable information (PII) and protected health information (PHI), including names, addresses, SSNs, and payment card info (but not numbers). The breach occurred on March 9, 2024. HealthEquity disabled compromised accounts, reset passwords, and offered two years of credit monitoring.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_e37a99ced8da956cNew Hampshire State AGfiled 2025-03-24(3d gap)Verified
- bd_055f9b1868e64ea8California State AGfiled 2025-04-09(19d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-600258
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 21, 2025
- Raw hash
- 527b4aeed609c72d9d4f92bf57012f8a2e0d5e51d7840a92216105b65304ae18
Reporting entity
- Name
- HEALTHEQUITY, INC.norm: healthequity
- Domain
- healthequity.com
Victim entity
- Name
- HEALTHEQUITY, INC.norm: healthequity
- Domain
- healthequity.com
Incident
- Discovered
- Mar 25, 2024
- Materiality determined
- —
- Notification sent
- Jun 26, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via Vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 52 weeks(361 days from discovery to filing)
- Compliance flags
- CA 60-day late · 93dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 25, 2024→ Notified: Jun 26, 202493d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.