HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
HEALTHEQUITY, INC.
bd_ab367867a391d767 · schema v1 · pii pii-v1
Full breach record for HEALTHEQUITY, INC. →HealthEquity, Inc. reported a data breach to the California Attorney General involving unauthorized access to employee email accounts. The incident occurred between September 4, 2018, and October 3, 2018, with discovery on October 5, 2018. Exposed data included Social Security numbers, names, and financial account details (HSA/FSA). HealthEquity secured accounts, notified law enforcement, and offered 5 years of credit monitoring and identity theft protection to affected individuals.
California clockDiscovered Oct 5, 2018 → Notified Nov 15, 201841d ✓ CA 60-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_3fb11c6dbb0d8a73Oregon State AGfiled 2018-11-15Verified
- bd_9cb6700363c2b53cWashington State AGfiled 2018-11-15Verified
- bd_ef7b85b1be28972cMontana State AGfiled 2018-11-15Verified
- bd_4726a001a35d8341HHS OCRfiled 2018-11-17(2d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-141841
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 15, 2018
- Raw hash
- 1cf8c1d90af4b94e02c9e9551a88e6e1eef7e6e3acb782807d66a1b64b2a9a2f
Reporting entity
- Name
- HEALTHEQUITY, INC.norm: healthequity
- Domain
- healthequity.com
Victim entity
- Name
- HEALTHEQUITY, INC.norm: healthequity
- Domain
- healthequity.com
Incident
- Discovered
- Oct 5, 2018
- Materiality determined
- —
- Notification sent
- Nov 15, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(41 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 41d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 5, 2018→ Notified: Nov 15, 201841d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.