HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTFINANCIAL_ACCOUNTMediumContained
HEALTHEQUITY, INC.
bd_7e9b16c89d34dab0 · schema v1 · pii pii-v1
Full breach record for HEALTHEQUITY, INC. →HealthEquity, Inc. reported a data security incident where a vendor's user accounts were compromised, leading to unauthorized access to personally identifiable information and protected health information. The breach occurred on March 9, 2024, and was discovered on March 25, 2024. Affected data included names, addresses, SSNs, and payment card information. HealthEquity engaged third-party experts, disabled compromised accounts, and offered two years of credit monitoring.
California clockDiscovered Mar 25, 2024 → Notified Jun 26, 202493d ✗ CA 60-day late14 months discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_6b441c84e03e4bf6Leak Sitecl0pfiled 2023-06-15(698d gap)Verified
Regulatory filings (4) · sorted by filing gap
- bd_3ad316c6fe8b921cMaine State AGfiled 2024-07-26(291d gap)Candidate
- bd_40e275097d04739aOregon State AGfiled 2024-07-26(291d gap)Verified
- bd_7caea854c6066af0Montana State AGfiled 2024-07-26(291d gap)Verified
- bd_e60b7bd89f1fbdd3Washington State AGfiled 2024-07-26(291d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-602630
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 13, 2025
- Raw hash
- dce1ba097ced00b42cd80e5e0bd66495354c17a5754c18f51b42f28df7357626
Reporting entity
- Name
- HEALTHEQUITY, INC.norm: healthequity
- Domain
- healthequity.com
Victim entity
- Name
- HEALTHEQUITY, INC.norm: healthequity
- Domain
- healthequity.com
Incident
- Discovered
- Mar 25, 2024
- Materiality determined
- —
- Notification sent
- Jun 26, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 14 months(414 days from discovery to filing)
- Compliance flags
- CA 60-day late · 93dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 25, 2024→ Notified: Jun 26, 202493d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.