Security

HealthEquity data breach affects 4.3M people

Comment

An Opened Prescription Medicine Bottle Among Many Other Sealed Bottles on Yellow Background High Angle View.
Image Credits: MirageC / Getty Images

HealthEquity is notifying 4.3 million people following a March data breach that affects their personal and protected health information.

In its data breach notice, filed with Maine’s attorney general, the Utah-based healthcare benefits administrator said that although the compromised data varies by person, it largely consists of sign-up information for accounts and information about benefits that the company administers.

HealthEquity said the data may include customer names, addresses, phone numbers, their Social Security number, information about the person’s employer and the person’s dependent (if any), and some payment card information. 

HealthEquity provides employees at companies across the United States access to workplace benefits, like health savings accounts and commuter options for public transit and parking. At its February earnings, HealthEquity said it had more than 15 million total customer accounts.

In its data breach notice, HealthEquity said it discovered the data breach after finding unauthorized access in an “unstructured data repository” outside of its core network that contained customers’ personal and health information. Some of the stolen data also includes information about diagnoses and prescriptions, the company said.

The notice said that the breach occurred because a user account of one of HealthEquity’s vendors was compromised and their password stolen, which was used by the malicious hacker to access the data repository.

When reached for comment, HealthEquity would not name the third-party vendor. The company previously told TechCrunch that the compromised third-party vendor account had access to “some of HealthEquity’s SharePoint data,” referring to Microsoft SharePoint, which allows companies to create their own internal intranets. 

Several other companies in recent years, including Activision, Snowflake, and Worldcoin, have experienced security incidents because of employee password theft, often by way of password-stealing malware, which scrapes the passwords and credentials found on an employee’s computer. Some password-stealing malware can skirt multifactor authentication, a security feature that can block some password theft attacks, by stealing session tokens, which are stored on an employee’s computer to keep them persistently logged in. When stolen, session tokens can be used to gain access to the company’s network as if the hacker was that employee.

HealthEquity spokesperson Stacie Saltzgiver reiterated that the data breach was an “isolated incident” and confirmed that it was unrelated to the recent breaches of customer data held by cloud giant Snowflake.

HealthEquity has published a data breach notification on its website. When TechCrunch checked the website notice, HealthEquity had included hidden “noindex” code on the page that tells search engines to ignore the web page, effectively blocking affected individuals from finding HealthEquity’s data breach notice in search results. 

When asked by TechCrunch, the company’s spokesperson did not comment on the inclusion of the code.

More TechCrunch

The software supply chain faces threats from all sides. A 2024 report by the Ponemon Institute found that over half of organizations have experienced a software supply chain attack, with…

Lineaje raises $20M to help organizations combat software supply chain threats

The founder of once-hyped crypto startup BitClout is facing trouble. On Tuesday, the SEC charged him with fraud and other offenses.

SEC charges BitClout founder Nader Al-Naji with fraud; says proceeds paid for L.A. mansion, gifts

For one thing, Wiz could have seen Google’s offer as validation that it’s better off staying independent.

It took some serious nerve for Wiz to walk away from Google’s $23B offer

OpenAI began rolling out ChatGPT’s Advanced Voice Mode on Tuesday, giving users their first access to GPT-4o’s hyper-realistic audio responses. The alpha version will be available to a small group…

OpenAI releases ChatGPT’s hyper-realistic voice to some paying users

The CNMC opened an investigation of Booking.com back in October 2022, following complaints by the Spanish Association of Hotel Managers and the Regional Hotel Association of Madrid.

Spain’s antitrust watchdog fines Booking.com nearly $450M for unfair terms and restricting rivals

The Kids Online Safety Act (KOSA) has passed in the Senate after Majority Leader Chuck Schumer (D-NY) pushed the internet bill to a vote. Proposed in 2022, KOSA requires that…

Controversial internet bill KOSA passed by Senate

Back in May, Spotify quietly started putting lyrics behind a paywall, limiting free users to lyrics for three songs per month. The move was a bid to push more users…

Spotify expands lyrics access for free users

Welcome to TechCrunch Fintech! This week, we’re looking at Stripe’s easy-peasy acquisition, the role fintech played in Clio’s latest raise, the latest with digital banking startup Mercury, and more.  To…

Fintech giant Stripe keeps on buying

Meta agrees to pay the state of Texas $1.4 billion over five years, and the first payment of $500 million is due in the next month, according to a court…

Meta will pay Texas $1.4B in settlement over facial recognition software

Airtable today announced that it has acquired Dopt, a startup focused on helping other startups build product onboarding experiences for new users. Earlier this year, Dopt introduced a number of…

Airtable acquihires onboarding startup Dopt for AI talent

AI hardware is all the rage in startup land — though receptions have thus far been mixed. Two notable examples, Rabbit and Humane, released devices to disappointing results. a16z-backed Limitless…

Friend’s $99 necklace uses AI to help combat loneliness

Europe is routinely castigated by tech industry observers for having too little “growth capital” funds, and, compared to the U.S., that’s true. That said, it is nowhere near nonexistent on…

Hey, there ARE growth funds in Europe — Kennet raises $287M for its largest fund to date

Intelmatix, a deep tech B2B startup that’s targeting businesses in the MENA (Middle East and North Africa) region wanting help to tap into the power of AI for decision-making, has…

Intelmatix raises $20M Series A to enable MENA businesses to tap AI for decision-making

We say something “goes viral” because we tend to think of rumors and disinformation spreading the way that an infection spreads. But these days it may be more accurate to…

Disinformation may ‘go nuclear’ rather than ‘go viral,’ researchers say

The fundraising environment is challenging for emerging managers, defined as VC firms raising their first through third time. But Katie Jacobs Stanton, a former head of media at Twitter who…

Moxxie Ventures, led by ex-Twitter media head, raises $95M third fund

Historically, passive income has been associated with investing in real estate such as rental properties. FranShares is a Chicago-based startup that wants to offer investors another form of passive income:…

FranShares has a new approach to passive income, letting people invest in franchises for as little as $500

Maximize your brand exposure at TechCrunch Disrupt 2024, one of the tech industry’s most anticipated events! From October 26 to November 1, you can host a Side Event, offering a…

Amplify your brand by hosting a Side Event at TechCrunch Disrupt 2024

HealthEquity said the March data breach included personal information and protected health data on millions of people.

HealthEquity data breach affects 4.3M people
Image Credits: MirageC / Getty Images

ClickHouse has made a name for itself as a real-time data warehouse for large enterprises. Its customer list includes Deutsche Bank, eBay, Fastly, GitLab, HubSpot, Microsoft, ServiceNow and Spotify.

Real-time database startup ClickHouse acquires PeerDB to expand its Postgres support

The EU has kicked off a consultation on rules that will apply to providers of general purpose AI models under the bloc’s AI Act.

EU calls for help with shaping rules for general-purpose AIs

Siddhi Capital’s second fund of $135 million is double the size of the venture capital firm’s first fund and will go into CPG and food tech startups.

Siddhi Capital grabs $135M for Fund II to invest in consumer packaged goods startups

Perplexity AI will soon start sharing advertising revenue with news publishers when its chatbot surfaces their content in response to a user query, a move that appears designed to assuage…

Perplexity details plan to share ad revenue with outlets cited by its AI chatbot

Women’s health tech, which leverages innovations in AI, smartphones and connected wearables to give women more insights into reproductive and menstrual health, continues to gain momentum with users, and investors…

Fertility tracking app Flo Health raises $200M at a $1B+ valuation

Meta said Monday that it is rolling out its AI studio to all creators in the U.S. to let them make personalized AI-powered chatbots. The company first announced the AI…

Meta is rolling out its AI Studio in the US for creators to build AI chatbots

The startup is betting it can bring its fusion technology to market at a breakneck pace by leaning heavily on partners.

Bill Gates-backed Type One Energy lands massive seed extension to commercialize fusion power

The U.K.’s antitrust regulator has revealed an early-stage probe into Google’s ties with Anthropic, after the Alphabet subsidiary invested in its U.S. AI rival over several rounds. While it’s not…

UK antitrust body probes Google’s ties with AI rival Anthropic

We’ve been covering U.S.-based insurtech startup Faye way back since 2022 with its seed round, and the Series A round in 2023, and it seems they continue to be on…

Packing travel insurance products into an app helped Faye to a $31M Series B

Sennder is acquiring the European ground transportation assets of logistics giant C.H. Robinson.

Sennder buys CH Robinson’s European business

When Egyptian B2B e-commerce platform Cartona last raised money in 2022, global and local investors were eager to invest in African startups solving the supply chain and operational challenges for…

Egypt’s Cartona raises $8.1M even as investors pull back from B2B e-commerce in Africa

During an emergency hearing held by the South Korean government, Young-bae Ku, Qoo10’s founder said he would secure the amount over the next 30 days.

Qoo10’s CEO pledges personal assets worth $58M to compensate Korean merchants affected by its liquidity crisis