On Tuesday, well being tech companies supplier HealthEquity disclosed in a submitting with federal regulators that it had suffered a data breach, during which hackers stole the “protected well being data” of some prospects.
In an 8-Okay submitting with the SEC, the corporate stated it detected “anomalous habits by a private use gadget belonging to a enterprise associate,” and concluded that the associate’s account had been compromised by somebody who then used the account to entry members’ data.
On Wednesday, HealthEquity disclosed extra particulars of the incident with TechCrunch. HealthEquity spokesperson Amy Cerny stated in an e mail that this was “an remoted incident” that is not related to different latest breaches, comparable to that of Change Healthcare, owned by the healthcare large UnitedHealth. In May, UnitedHealth CEO Andrew Witty stated in a House listening to that the breach affected “possibly a 3rd” of all Americans.
HealthEquity detected the breach on March 25, when it “took fast motion, resolved the problem, and commenced intensive data forensics, which have been accomplished on June 10.” The firm introduced collectively “a group of outdoor and inside consultants to research and put together for response.” The investigations decided that the breach was as a result of compromised third-party vendor account gaining access to “a few of HealthEquity’s SharePoint data,” based on Cerny.
Contact Us
Do you might have extra details about this HealthEquity breach? From a non-work gadget, you’ll be able to contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or by way of Telegram, Keybase and Wire @lorenzofb, or e mail. You can also contact TechCrunch by way of SecureDrop.
SharePoint is a set of Microsoft instruments that permits corporations to create web sites, in addition to retailer and share inside data — basically an intranet.
Cerny additionally stated that “transactional programs, the place integrations happen, weren’t impacted,” and that the corporate is notifying companions, shoppers and members, and has been working with regulation enforcement in addition to consultants to work on stopping future incidents.
TechCrunch requested Cerny to specify what personally identifiable and “protected well being” data was stolen on this breach, how many individuals have been affected and what associate was concerned. Cerny declined to reply all of those questions.
Earlier this 12 months, HealthEquity reported that the corporate and its subsidiaries “administer HSAs and different CDBs for our greater than 15 million accounts in partnership with employers, advantages advisers, and well being and retirement plan suppliers.”



