Soon after discovering, the officials suspended the account and began investigating the matter. The investigations revealed compromise of data of around 23000 individuals. Predominantly, it belonged to two Michigan-based companies working with HealthEquity. The compromised data included names of employees and employers, HealthEquity member IDs, healthcare account details, deduction amounts, and social security numbers of the employees.
After the data breach, HealthEquity offered five years of credit monitoring and identity theft protection services to the affected companies. In this regard, Joel Johnson, Senior Vice President Audit & Risk Management says that HealthEquity cares about the security of its customers.
“That is a long time to provide credit monitoring and identity protection, as most organizations offering protection offer one year, with some providing two years. But HealthEquity wants its customers to know that their well-being is paramount.”Tim Erlin, Vice President Product Management & Strategy at Tripwire says that healthcare sector is becoming prone to cyber attacks owing to the ‘highly valuable’ information it stores. He also appreciates the vigilance of HealthEquity to discover the data breach within two days.
“The fact that this breach was detected two days after it occurred is notable and a sign that HealthEquity was paying attention.”HealthEquity is a non-bank health savings company based in Draper, UT. The company holds data of around 3.4 million accounts as disclosed on their website. These include Health Savings Accounts (HSA), 401(k) Retirement accounts, and Flexible Spending Accounts (FSA) along with other services for about 40,000 companies.