All Breaches
March 25, 2024 Verified Healthcare and financial services

HealthEquity 2024

The HealthEquity 2024 data breach emerged when the company, providing services in the fields of health savings accounts and employee benefits management, announced an access incident related to an external service. The company stated that it became aware of a system anomaly on March 25, 2024, that the technical review and forensic analysis process lasted until June 10, 2024, and that on June 26, 2024, it confirmed that personal information of some members was included in the scope of the incident. The incident was associated with unauthorized access or potential disclosure in an unstructured data repository located outside the company's main systems.

This record represents a large-scale breach that may have affected personal data associated with HSA, FSA, HRA, commuter, COBRA, and similar fringe benefit programs managed by HealthEquity. The reported main scope is approximately 4.3 million individuals. The types of leaked data are not limited to simple contact information; highly sensitive areas such as Social Security number, health card number, health plan member number, type of service, diagnosis information, prescription details, and payment card information are also listed. It is specifically noted that, on the payment card side, the card number or HealthEquity debit card information is not included.

The critical point of the HealthEquity incident is that health and financial benefits data are present in the same context. Such data can help attackers create convincing scenarios about a person's employer, health plan, type of services they are enrolled in, and authentication information. It has not been indicated that all data fields have been leaked for each affected individual; therefore, risk assessment should be made based on the fields seen in individual notifications. Nevertheless, the record should be considered high-priority in terms of identity theft, health fraud, fake benefits claims, and targeted social engineering.

Leaked Data Types and Risks

Declared data classes include first and last name, physical address, phone number, employee number, employer information, social security number, health card number, health plan member number, dependent information, type of service, diagnosis information, prescription details, and payment card information. The combination of these fields can create a detailed profile of the user's identity as well as their health benefits profile. In particular, persistent identifiers such as social security number and health plan member number pose a risk for a longer period than a password.

Address, phone number, and employer information can be used in targeted call or text message fraud. Diagnosis and prescription information carry a high level of privacy sensitivity and can be misused to create convincing fake requests related to healthcare services. Although it is stated that payment card numbers are not included, the term payment card information requires users to carefully review account transactions and fringe benefit expenditures. The most important risk in this incident is the combined use of the data, not their separate use.

Verified Scope and Boundaries

The verified main impact is approximately 4.3 million people. The incident is associated with unauthorized access or potential disclosure in an unstructured data repository related to services controlled by the company rather than HealthEquity's main processing systems. The company reported that external service provider accounts have been deactivated, sessions have been terminated, addresses associated with the threat activity have been blocked, and a general password reset has been performed for the affected service provider. This information indicates that the incident should be understood as data access occurring through specific access paths rather than a disruption spread directly across all core systems.

In this record, the data fields are limited to the categories explicitly listed in the main notification. It has been stated that not every individual is affected by all fields. In addition, since it was indicated that the payment card number and HealthEquity bank card information are out of scope, this record has not been flagged as a payment card number leak. Some sub-notifications from partners or health plans may show narrower or different fields; this record is based on the scope of the main notification, which covers 4.3 million individuals.

User Groups at Risk

At-risk groups consist of members using a health savings account or employer-sponsored fringe benefit account through HealthEquity, employees, family members, and individuals included as dependents under the plan. For affected individuals, fabricated human resources messages, benefit update requests, or payment routing attempts can become more convincing. The health plan member number and type of service information can provide specific clues about which type of health or fringe benefit service the user is utilizing.

For users whose information includes dependent individuals, family members may also be indirectly at risk. Information registered on behalf of children or spouses can pose a long-term identity risk because these individuals may not regularly review their own credit or health records. For individuals with diagnosis and prescription information at risk, the loss of privacy is more severe; this information should be considered not only in terms of financial harm but also in terms of social pressure, blackmail, and healthcare fraud.

Urgent Measures to Be Taken

Users matching this record should first check their profile information, address and phone records, recent account activity, and reimbursement requests in their HealthEquity and related fringe benefit accounts. If any unexpected payment, new card request, account routing, employer change, or reimbursement transaction is observed, one should contact the institution directly through known official channels. Instead of links received via email or text message, it is more accurate to log in by typing the known address into the browser manually.

Users whose social security number, health plan member number, or health card information may have been compromised should consider credit freezing, fraud alerts, and checking their credit report. Users at risk for health data should review not only their financial accounts but also their healthcare statements, benefits spending records, and prescription history. If the same username or contact information is used on other accounts, strong unique passwords and multi-factor authentication should be used on important accounts.

Long-Term Security Strategies

The HealthEquity 2024 breach shows that employee benefits and health financing records remain valuable for a long time. Social Security numbers, health plan member numbers, employer information, and diagnosis data are not simple account details that can be changed. Therefore, monitoring for only a few weeks after the initial notification is not sufficient. Users should regularly review credit files, health statements, benefits account transactions, and tax-related documents throughout the year.

From the employers' perspective, two-channel verification, access limits for service provider accounts, role-based access on fringe benefit platforms, and suspicious transaction alerts are important. Employees should be reminded not to share identity and payment information in messages that appear to be from human resources or related to fringe benefit updates. Individual users, on the other hand, should be more cautious with messages containing details that appear correct, such as employer name, health plan, or type of service; messages containing real details should not automatically be considered trustworthy.

Record Control and User Action

Seeing a match with this record on LeakData indicates that the user's information may be included in the main scope associated with the HealthEquity 2024 data breach. When a match is found, it should first be determined which identity or contact information triggered the alert, and then the HealthEquity account, employer benefits system, credit reports, and healthcare statements should be examined in order. Since a password leak was not indicated as a primary area in this incident, simply changing the password is not a sufficient security measure.

Users should inquire without delay about unexpected health services, prescriptions, reimbursements, or ancillary benefit transactions. In suspicious phone calls, identity information, social security number, health plan number, or payment information should not be shared. When long-term monitoring, credit freezing, and regularly checking health records are applied together, the persistent risks that such widespread health and ancillary benefit data breaches can cause can be detected earlier.

4.3 Million
Affected Accounts
13
Data Types
Critical
Severity
Yes
Verification

Exposed Data Types

13
Names
Physical addresses
Phone numbers
Employee ids
Employer information
Social security numbers
Health card numbers
Health plan member numbers
Dependent information
Service types
Diagnoses
Prescription information
Payment card information

Additional Information

Added DateJuly 9, 2026
Breach DateMarch 25, 2024
Domainhealthequity.com
SourceOfficial company disclosure and regulatory notifications
Last Content UpdateJuly 19, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information