HealthEquity says data breach is an ‘isolated incident’

Date:

Share post:


On Tuesday, health tech services provider HealthEquity disclosed in a filing with federal regulators that it had suffered a data breach, in which hackers stole the “protected health information” of some customers. 

In an 8-K filing with the SEC, the company said it detected “anomalous behavior by a personal use device belonging to a business partner,” and concluded that the partner’s account had been compromised by someone who then used the account to access members’ information.

On Wednesday, HealthEquity disclosed more details of the incident with TechCrunch. HealthEquity spokesperson Amy Cerny said in an email that this was “an isolated incident” that is not connected to other recent breaches, such as that of Change Healthcare, owned by the healthcare giant UnitedHealth. In May, UnitedHealth CEO Andrew Witty said in a House hearing that the breach affected “maybe a third” of all Americans.

HealthEquity detected the breach on March 25, when it “took immediate action, resolved the issue, and began extensive data forensics, which were completed on June 10.” The company brought together “a team of outside and internal experts to investigate and prepare for response.” The investigations determined that the breach was due to the compromised third-party vendor account having access to “some of HealthEquity’s SharePoint data,” according to Cerny.

Contact Us

Do you have more information about this HealthEquity breach? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

SharePoint is a set of Microsoft tools that allows companies to create websites, as well as store and share internal information — essentially an intranet.

Cerny also said that “transactional systems, where integrations occur, were not impacted,” and that the company is notifying partners, clients and members, and has been working with law enforcement as well as experts to work on preventing future incidents. 

TechCrunch asked Cerny to specify what personally identifiable and “protected health” information was stolen in this breach, how many people have been affected and what partner was involved. Cerny declined to answer all of these questions. 

Earlier this year, HealthEquity reported that the company and its subsidiaries “administer HSAs and other CDBs for our more than 15 million accounts in partnership with employers, benefits advisers, and health and retirement plan providers.”



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

The ‘Mozart of Math’ isn’t worried about AI replacing math nerds — ever

Terence Tao, a UCLA professor considered to be the “world’s greatest living mathematician,” last month compared ChapGPT’s...

YouTube apologizes for falsely banning channels for spam, canceling subscriptions

A misfire of YouTube’s systems led to the accidental banning of YouTube channels affecting numerous creators who...

OpenAI secured more billions, but there’s still capital left for other startups

Welcome to Startups Weekly — your weekly recap of everything you can’t miss from the world of...

Every fusion startup that has raised over $100M

Over the last several years, fusion power has gone from the butt of jokes — always a...

GM is working on an eyes-off, hands-off driving system

Seven years ago, GM became the first automaker to offer hands-free driving when it rolled out its...

Fisker faces SEC investigation as bankruptcy case drags on

Bankrupt EV startup Fisker is under investigation by the U.S. Securities and Exchange Commission, according to a...

Announcing the final agenda for the SaaS Stage at TechCrunch Disrupt 2024

Software as a service (SaaS) is an ever-evolving industry. We’ll talk to some of the brightest minds...

Amazon closes more of its cashierless convenience stores

Amazon continues to scale back efforts around its cashierless checkout technology, Just Walk Out. The e-commerce giant closed...