Well being know-how providers supplier HealthEquity on Tuesday disclosed in a federal regulatory submitting that it had fallen sufferer to an information breach through which hackers stole “protected well being info” of a few of its clients.
SEC 8-K filingsThe corporate stated it detected “uncommon conduct from a enterprise associate’s private gadget” and concluded that the account had been compromised by somebody who used it to entry members’ info.
HealthEquity shared particulars of the incident with TechCrunch on Wednesday. HealthEquity spokesperson Amy Cerny stated in an e mail that it was an “remoted incident” and never associated to different current knowledge breaches, similar to at Change Healthcare, which is owned by well being care large UnitedHealth. UnitedHealth CEO Andrew Whitty stated at a Home of Representatives listening to in Might that the breach affected “most likely a 3rd” of all People.
HealthEquity found the breach on March 25 and “took instant motion to remediate the difficulty and initiated an intensive knowledge forensic investigation that was accomplished on June 10.” The corporate “assembled a staff of exterior and inside consultants to analyze and put together for our response.” In line with Cerny, the investigation decided that the breach was the results of a compromised third-party vendor account that accessed “a few of HealthEquity’s SharePoint knowledge.”
inquiry
Have extra details about the HealthEquity breach? You may securely contact Lorenzo Franceschi-Bicchierai from a non-work gadget through Sign (+1 917 257 1382), Telegram, Keybase, Wire @lorenzofb, or e mail. It’s also possible to contact TechCrunch through SecureDrop.
Sharepoint is a set of Microsoft instruments that enables companies to create web sites and retailer and share inside info — primarily an intranet.
Cerny additionally stated that “the transactional methods by means of which the mixing takes place weren’t affected,” and that the corporate has notified companions, clients and members, and is working with legislation enforcement and consultants to forestall future incidents.
TechCrunch requested Cerny about what private and “protected well being” info was stolen within the breach, how many individuals had been affected, which companions had been concerned, and many others. Cerny declined to reply all of those questions.
Earlier this 12 months, HealthEquity reported The corporate and its subsidiaries “associate with employers, advantages advisors, and well being and retirement plan suppliers to manage HSAs and different CDBs for greater than 15 million accounts.”

