HealthEquity, the covered entity (CE), reported that several employees were the victims of an email phishing attack. The breached accounts contained the protected health information (PHI) of 165,800 individuals. The PHI involved included names and Social Security numbers. HealthEquity conducted a forensic analysis and notified HHS, affected individuals, and the media. As a result of this breach, the CE implemented additional administrative, technical, and security safeguards and trained its staff on the proper methods for identifying fraudulent email communications. OCR provided technical assistance on how HealthEquity could better protect its PHI and reduce the amount of sensitive data vulnerable to attack. OCR obtained assurances that the CE implemented the aforementioned corrective actions.
2026-09-25 · disclosed: 2018-06-13 to 2018-06-12 · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 165800 · backfill source
2026-09-25 · summary: empty to HealthEquity, the covered entity (CE), reported that several employees were the victims of an email phishing attack. The breached accounts contained the protected health information (PHI) of 165,800 individuals. The PHI involved included na · backfill source
2026-09-25 · data_types: [] to ["names","ssn","health","insurance"] · backfill source
2026-09-25 · disclosed: 2018-11-15 to 2018-06-13 · backfill source
2026-09-25 · attack: unknown to phishing · backfill source
2026-09-25 · discovered: empty to 2018-10-05 · backfill source