Clustered 3 filings across 2 jurisdictions · filing window Mar 21, 2025 → Apr 9, 2025. View entity profile → Other incidents for this victim →
incident inc_d0fdd884087c498e · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Government ID · Financial account
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA NH
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Mar 9, 2024
When the intrusion reportedly occurred, per the linked filings
Mar 25, 2024
Reported by CALIFORNIA AG, NEW HAMPSHIRE AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
HealthEquity, Inc. reported a data breach affecting HSA/FSA customers. On March 25, 2024, the company detected a systems anomaly. Investigation revealed that a third-party vendor's user accounts were compromised, allowing unauthorized access to an online data storage location containing personally identifiable information (PII) and protected health information (PHI), including names, addresses, SSNs, and payment card info (but not numbers). The breach occurred on March 9, 2024. HealthEquity disabled compromised accounts, reset passwords, and offered two years of credit monitoring.
HealthEquity, Inc. reported unauthorized access to an unstructured data repository containing PHI and PII of HSA/FSA plan participants. The anomaly was detected on March 25, 2024, following a vendor alert. Forensic investigation confirmed unauthorized access and potential disclosure. HealthEquity is a third-party administrator for healthcare benefits.
HealthEquity, Inc. reported a data security incident where a vendor's user accounts were compromised, leading to unauthorized access to personally identifiable information and protected health information. The breach occurred on March 9, 2024, and was discovered on March 25, 2024. Affected data includes names, addresses, SSNs, and payment card info. HealthEquity engaged third-party experts, disabled compromised accounts, and offered two years of credit monitoring.