[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1f1gjfepepwid":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":13,"affectedCount":13,"affectedCountStatus":21,"affectedCountLowerBound":13,"affectedCountUnit":22,"hasEnglishDescription":4,"contentLocale":23,"availableLocales":24,"translations":26,"severity":29,"dataClasses":30,"description":39,"seoTitle":8,"seoDescription":40,"logoUrl":41,"isVerified":4,"isSensitive":4,"isSpamList":42,"isMalware":42,"company":43},"6a4f7f55b80e275466ce5f47","HealthEquity 2024","HealthEquity 2024 Data Breach","healthequity-2024","healthequity.com","2024-03-09T00:00:00.000Z","2026-07-09T11:00:37.271Z",null,"2026-07-29T11:13:00.741Z","Official HealthEquity notice, SEC filing, and regulator notifications","https:\u002F\u002Fwww.healthequity.com\u002Fbreach",[16,18,19,20],"https:\u002F\u002Fwww.maine.gov\u002Fagviewer\u002Fcontent\u002Fag\u002F985235c7-cb95-4be2-8792-a1252b4f8318\u002F2ec3e314-5731-49d0-a937-6dc22c6b24f3.html","https:\u002F\u002Fwww.sec.gov\u002FArchives\u002Fedgar\u002Fdata\u002F1428336\u002F000142833624000055\u002Fhqy-20240702.htm","https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf","unknown","people","en",[23,25],"tr",{"en":27,"tr":28},{"slug":9},{"slug":9},"Unknown",[31,32,33,34,35,36,37,38],"Names","Physical addresses","Phone numbers","Employee IDs","Employer information","Social Security numbers","Dependents’ general contact information","Payment card information excluding payment-card numbers and HealthEquity debit-card information","\u003Cp>\u003Cstrong>The 2024 HealthEquity data breach\u003C\u002Fstrong> involved a compromised business-partner account used to access online unstructured storage outside core systems. A regulator filing records March 9, 2024 as the known breach date. HealthEquity received an anomaly alert on March 25, forensic work continued through June 10, and on June 26 it confirmed that information associated with some recipients was involved.\u003C\u002Fp>\u003Cp>According to the SEC filing, anomalous behavior was observed from the partner's personal-use device, an unauthorized party used the partner account to access information, and some information was transferred off partner systems. No malicious code or service interruption was found on HealthEquity systems. The company said it disabled accounts and sessions, blocked IP addresses, and required a vendor-wide password reset.\u003C\u002Fp>\u003Cp>Approximately 4.3 million potentially affected individuals is a notification population, not accounts, local records, emails, or passwords. The main sample notice lists names, addresses, phones, employee IDs, employers, Social Security numbers, dependents' general contact information, and some payment-card information excluding payment-card numbers and HealthEquity debit-card information. Fields varied by recipient; diagnoses, prescriptions, service types, and health-plan numbers require separate client-specific notice evidence.\u003C\u002Fp>\u003Cp>No person-level corpus exists locally. The event does not associate anyone with a HealthEquity or WageWorks account, employee, member, or dependent status, a particular employer, health condition, or payment information. Social Security, dependent, employer, health, and payment data must remain private, and only direct recipients should rely on the fields and service terms in their own notices.\u003C\u002Fp>","HealthEquity 2024 Data Breach. The affected total has not been disclosed. Reported data: Names, Physical addresses, Phone numbers. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fhealthequity-2024.svg",false,{"name":44,"sector":45,"country":46,"website":10,"websiteArchiveUrl":47,"websiteStatus":47,"websiteCheckedAt":13},"HealthEquity, Inc.","Healthcare and financial services","United States",""]