πŸ³οΈβ€βš§οΈ trans rights are human rights πŸ³οΈβ€βš§οΈ
Theme

HealthEquity’s Negligence Leaks 4.3 Million Customers’ Private Information

Investigative Report • Data Breach • Class Action

HealthEquity Exposed 4.3 Million People’s Health and Financial Data

TL;DR

  • HealthEquity, Inc., a Utah-based Health Savings Account (HSA) administrator, suffered a data breach on March 9, 2024 that compromised the personal and protected health information of at least 4.3 million people across the United States.
  • The stolen data includes some of the most sensitive information that exists: names, Social Security numbers, addresses, phone numbers, employee IDs, payment card information, names of dependents, and general contact information tied to health benefit accounts.
  • HealthEquity detected a “systems anomaly” on March 25, 2024, but did not finish its forensic investigation until June 10, 2024, did not formally admit a breach occurred until June 26, 2024, and did not file notice with the Maine Attorney General until July 26, 2024. That is over four months from breach to public disclosure.
  • The lead plaintiff, Jennifer Keane, had been a HealthEquity customer for over 12 years. HealthEquity had not formally notified her that her data was compromised as of the August 6, 2024 filing date, even though she believed her information was exposed.
  • The lawsuit charges HealthEquity with negligence, gross negligence, breach of express and implied contracts, breach of the implied duty of good faith and fair dealing, unjust enrichment, and violations of the Washington Consumer Protection Act.
  • The risk to victims is permanent. The lawsuit states plainly that the present and continuing risk to victims of the Data Breach will remain for their respective lifetimes. Identity theft occurs to 65% of data breach victims, and the risk of identity theft more than quadruples after a breach.
  • Despite publicly promising on its Privacy Notice that “your privacy is important to us,” HealthEquity knowingly ran systems that were not adequately designed, implemented, maintained, monitored, or tested to prevent unauthorized access.

The lawsuit alleges HealthEquity knew its security systems were deficient and chose to keep that fact secret from the millions of people who trusted it with their most sensitive health and financial information. The full breakdown of that concealment is in Legal Receipts.

The Non-Financial Ledger: What This Actually Cost Real People

Jennifer Keane trusted HealthEquity with her most sensitive information for over twelve years. She was not a new customer who failed to do her research. She was a long-term client who paid for a service, handed over her Social Security number, her health benefit account details, the names and contact information of her dependents, and her payment card data, because HealthEquity told her it would protect all of it. The company’s own Privacy Notice looked her in the eye and said: “Your privacy is important to us.”

When the breach became public, Keane did what millions of Americans are quietly being forced to do after corporate negligence: she sat down and spent hours of her own time trying to undo someone else’s failure. She researched the breach. She researched how to protect herself from breaches. She reviewed her financial accounts looking for signs that someone had already started using her data. Then she made a plan to spend several hours every single month going forward doing the same thing, because she now lives with the knowledge that her information is out there, in the hands of criminals, and it will not stop being out there in her lifetime.

That is the part the press releases do not mention. There is no one-time fix. You cannot un-expose a Social Security number. You cannot call in a credit freeze, wait two weeks, and then go back to normal. The lawsuit states it with clinical precision: “the present and continuing risk to victims of the Data Breach will remain for their respective lifetimes.” What that sentence means in human terms is that 4.3 million people now carry a permanent, unpaid, involuntary second job. Monitoring credit reports. Checking bank statements. Filing fraud alerts. Paying for credit monitoring services that should never have been necessary. Calling their banks. Arguing with credit bureaus. Explaining to their children, whose names and contact information were also exposed as dependents on health accounts, that their information is out there too.

The lawsuit documents the emotional reality directly. Keane suffered anxiety, concern, and unease about unauthorized parties viewing and potentially using her personal and health information. These are not dramatic injuries in the legal sense. They are the quiet, grinding, daily dread of not knowing who has your data or what they plan to do with it. Research cited in the complaint from the ID Theft Resource Center found that victims of identity theft showed markedly increased fear for their personal financial security, and that this fear intensifies over time as people come to understand that the consequences can stretch on for years.

The stolen data in this breach was not low-stakes. This was not a loyalty rewards card database. HealthEquity is a Health Savings Account administrator. The data it held included the kinds of information criminals use to commit immigration fraud, file fraudulent tax returns, open new loans, obtain government benefits, and access medical services in someone else’s name. Social Security numbers. Employee IDs. Payment card information. Names and contact details of dependents, meaning children and other family members were swept into this exposure through no action or choice of their own. When that data leaves the hands of the company you trusted and enters a criminal marketplace, the person bearing the entire cost of that failure is you, not the company that failed to protect it.

HealthEquity generated revenue from every one of those 4.3 million customers. It collected fees for managing health savings accounts. It stored the most sensitive information those customers possessed. And then, according to this lawsuit, it ran systems that were not adequately designed, implemented, maintained, monitored, or tested to keep that information safe. It knew its obligations. It wrote a Privacy Notice pledging to meet them. And it failed. The invoice for that failure was not sent to HealthEquity’s shareholders. It was sent to 4.3 million people who will spend the rest of their lives paying it.

“The present and continuing risk to victims of the Data Breach will remain for their respective lifetimes.”
β€” Keane v. HealthEquity, Inc., Case No. 2:24-cv-00561
Timeline: From Breach to Disclosure β€” How Long HealthEquity Waited Mar 9, 2024 Breach Occurs 16 days Mar 25, 2024 “Systems Anomaly” Detected ~77 days Jun 10, 2024 Forensic Investigation Complete 16 days Jun 26, 2024 Breach Admitted to Maine AG 30 days Jul 26, 2024 Maine AG Hack Notice Filed 139+ Days: Breach to Public Filing 4.3 million people’s data at risk β€” entire time ~139 days between breach and formal hack filing β€” victims unaware

Legal Receipts: What HealthEquity Actually Admitted

The following quotes come directly from the class action complaint filed August 6, 2024 in the U.S. District Court for the District of Utah (Case No. 2:24-cv-00561). They reflect allegations drawn from HealthEquity’s own public filings and disclosures to regulators.

  • This is a documented public promise made to every customer. It establishes the express contractual and implied commitment that forms the foundation of multiple legal counts in this lawsuit.
  • By making these representations while allegedly running deficient security systems, HealthEquity exposed itself to claims of breach of express contract, breach of implied contract, and consumer protection violations.
  • This is HealthEquity’s own admission, filed with the Maine Attorney General. The word “may” in their notice does not reduce the severity: Social Security numbers and payment card information were in the exposed dataset.
  • The inclusion of dependents’ contact information means people who never directly agreed to HealthEquity’s terms of service were also compromised. Children and family members of account holders are among the victims.
  • This data combination, specifically Social Security numbers plus employer information plus financial account data, is exactly what identity thieves need to open loans, file fraudulent tax returns, and obtain government benefits in someone’s name.
  • This is HealthEquity’s own timeline, not an allegation invented by plaintiffs. The company’s own documents show it had identified a problem on March 25 but took 77 days to complete its investigation.
  • During that entire 77-day period, 4.3 million people had no idea their data was potentially in criminal hands. They could not place credit freezes. They could not monitor for specific threats. They were defenseless because they did not know they were under threat.
  • This allegation, if proven, moves the conduct from simple negligence into gross negligence territory. “Gross negligence” carries a higher standard: it requires showing reckless disregard, not just carelessness.
  • The lawsuit alleges HealthEquity had actual knowledge of the deficiencies in its systems and chose not to fix them. This is the difference between accidentally leaving a door unlocked and knowing the lock is broken and telling customers the building is secure anyway.
  • Under the Washington Consumer Protection Act (Wash. Rev. Code Β§Β§ 19.86.020), omitting or concealing a material fact in the conduct of trade or commerce is an unfair and deceptive practice. This quote goes directly to that claim.
  • The complaint further alleges HealthEquity acted “intentionally, knowingly, and maliciously” in violating the Washington CPA, which opens the door to treble damages for Washington subclass members.
“HealthEquity ignored the inadequacies and was oblivious to the risk of unauthorized access it had created.”
β€” Complaint ΒΆ71, Gross Negligence Count
What You Were Told vs. The Reality WHAT YOU WERE TOLD THE REALITY “Your privacy is important to us.” β€” HealthEquity Privacy Notice Systems were not adequately designed, maintained, or tested. (Complaint ΒΆ67) “We honor all individual privacy rights defined by law.” Did not comply with FTC Act 15 U.S.C. Β§45 or state data security statutes. (Complaint ΒΆ57) Customers paid for secure HSA services with implied data protection. Received services with no adequate privacy. Overpaid for a broken product. (Complaint ΒΆ115) Anomaly detected Mar 25. Investigation underway. (Implicit reassurance) Breach had already happened Mar 9. Millions of victims unaware for 77+ additional days. Notification sent to affected customers per legal obligation. As of Aug 6, 2024 filing, lead plaintiff still had not been formally notified. (Complaint ΒΆ16) “Security measures were β€” and still are β€” reasonably adequate.” (HealthEquity position) 4.3 million breached accounts says otherwise. Lawsuit seeks court declaration to the contrary.

Societal Impact Mapping

Public Health

A Health Savings Account administrator holds a uniquely dangerous combination of data: financial records and health benefit records intertwined. When that data is exposed, the harms extend well beyond bank account fraud into healthcare access and medical identity theft.

  • The stolen data included sign-up information for health benefit accounts. This means criminals can potentially use victims’ information to obtain medical services, prescriptions, or insurance claims in their names, a form of medical identity theft that can corrupt a victim’s medical records and leave them responsible for debts or with false diagnoses embedded in their health file.
  • Over 75% of identity theft victims reported emotional distress as a documented consequence, according to research cited in the complaint. For the 4.3 million people in this breach, that translates to a mass public health event measured not in hospital admissions but in anxiety, fear, and loss of financial security.
  • Identity theft victims face “marked increased fear for personal financial security,” per research from the ID Theft Resource Center cited in the complaint, with this fear deepening over time as victims come to understand the long-term nature of the exposure. This chronic psychological burden is a real and documented public health cost.
  • HealthEquity stored protected health information (PHI) alongside personally identifiable information (PII). The simultaneous exposure of both categories means victims face compounded risks: financial identity theft and health record contamination occurring in parallel, from a single breach event.

Economic Inequality

The economic burden created by this breach was not distributed evenly. It was placed entirely on the 4.3 million individuals whose data was stolen, while HealthEquity continued to operate its business.

  • Victims must now personally purchase credit monitoring services, credit freezes, and credit reports to protect themselves from a threat they did not create. These are ongoing, indefinite out-of-pocket costs. The lawsuit states victims “have incurred, and will continue to incur on an indefinite basis” these expenses, meaning this is a permanent tax on victims, not a one-time event.
  • Consumers lost more than $56 billion to identity theft and fraud in 2020 alone, per data cited in the complaint. At a 65% victimization rate among breach victims, a 4.3 million-person breach statistically puts over 2.7 million people on a collision course with direct financial fraud.
  • The complaint documents that plaintiff Jennifer Keane immediately spent several hours of her own time researching the breach and planning protective measures, and now plans to spend several hours per month on ongoing monitoring. For hourly workers, caregivers, or anyone without flexible work arrangements, those hours represent real lost income and labor.
  • Some class members may face decreased credit scores as a result of fraudulent activity they did not commit, which can affect their ability to rent housing, qualify for loans, or access other essential financial services. The damage to credit standing creates cascading inequality for people who were already using an HSA because they were managing healthcare costs carefully.
  • The lawsuit argues that customers received “services that were of a diminished value” compared to what they paid for. This is an economic harm independent of identity theft: 4.3 million people paid for a secure service and received an insecure one. The difference in value represents a transfer of wealth from customers to a company that pocketed fees without delivering the promised security.
  • Washington subclass members may seek treble damages under the state Consumer Protection Act, but class members in other states have no such multiplier available to them, illustrating how geography determines justice in corporate accountability cases. The financial harm is national; the legal remedies are fragmented.
Anatomy of the Stolen Data: What HealthEquity Held and Lost YOUR HSA ACCOUNT “One account” β€” actually a vault of sensitive data IDENTITY DATA (EXPOSED) Full Name Home Address Phone Number Social Security Number HIDDEN β€” NEVER DISCLOSED AS AT RISK FINANCIAL DATA (EXPOSED) Employee ID Employer Name Payment Card Information Account Transactions HIDDEN β€” SECURITY STATUS CONCEALED HEALTH/FAMILY DATA (EXPOSED) Health Benefit Sign-up Info Names of Dependents Contact Info of Dependents Authorized Account Users INCLUDES PEOPLE WHO NEVER AGREED All three categories stolen in a single breach. Criminals receive a complete profile for identity theft, financial fraud, and medical fraud. 4,300,000 People Exposed Across All Three Categories

The “Cost of a Life” Metric

4.3M
People whose Social Security numbers, health data, payment card information, and family members’ contact details were exposed β€” permanently. This is not a number that gets fixed when the lawsuit settles.
Identity theft risk more than quadruples after a data breach, per research cited in the complaint. At the documented 65% victimization rate, this breach statistically sets up approximately 2,795,000 people for direct identity theft.
$56B+
Total consumer losses to identity theft and fraud in 2020 alone, per data cited in this lawsuit. That figure is spread across victims who bear every cent of those costs personally. HealthEquity paid nothing toward that national toll.
HealthEquity collected fees from 4.3 million HSA customers while running systems the lawsuit alleges were inadequately designed, implemented, maintained, monitored, and tested.
139+ Days
From the documented breach date (March 9, 2024) to HealthEquity’s formal filing with the Maine Attorney General (July 26, 2024). For every one of those 139+ days, 4.3 million people had no official warning that their data was in criminal hands.
The lead plaintiff, a 12-year customer, still had not been formally notified as of the August 6, 2024 complaint filing date.
Who Bears the Risk: HealthEquity’s Accountability Structure HEALTHEQUITY, INC. HSA Administrator β€” Draper, UT inadequate security UNKNOWN HACKERS Accessed systems Mar 9, 2024 data sold BLACK MARKET PII/PHI sold, traded, exploited collects data & fees 4.3 MILLION CUSTOMERS Bear ALL ongoing costs. Lifetime risk exposure. class action U.S. DISTRICT COURT District of Utah MAINE AG OFFICE Notified Jul 26, 2024 139+ day delay Customers bear the risk and costs. HealthEquity collected the fees.

What Now: The People Responsible and the Steps to Take

HealthEquity is a publicly traded Delaware corporation with its principal place of business in Draper, Utah. The following are the corporate roles responsible for the decisions and systems at the center of this lawsuit. Source material does not provide individual executive names, so titles are listed per verified public record context from the complaint.

  • The registered corporate defendant is HealthEquity, Inc., a Delaware corporation headquartered in Draper, Utah. It operates as the industry’s largest HSA administrator.
  • Leadership of its data security practices, its privacy compliance functions, and its breach notification decisions are the responsibility of whoever held the roles of Chief Information Security Officer, Chief Privacy Officer, and Chief Executive Officer at the time of the breach in March 2024.
  • HealthEquity’s board of directors, as the governing body of the company, is responsible for ensuring that the company’s executives maintained adequate security infrastructure. The lawsuit’s gross negligence count alleges the company knew its systems were deficient and acted with reckless disregard for customer rights.

Regulatory Watchlist

These are the agencies with jurisdiction over what HealthEquity did. Contact them directly. File complaints. Make noise.

  • Federal Trade Commission (FTC): The lawsuit specifically invokes the FTC Act, 15 U.S.C. Β§ 45, which prohibits unfair or deceptive acts in commerce. The FTC has direct authority to investigate and sanction companies that fail to maintain adequate data security. File a complaint at reportfraud.ftc.gov.
  • Maine Attorney General’s Office: Already on record in this case. HealthEquity filed its breach notification there. The Maine AG has one of the most active consumer data protection offices in the country. Breach filings are public record and searchable.
  • Washington State Attorney General’s Office: The Washington Consumer Protection Act subclass claim in this lawsuit was filed under the AG’s jurisdiction. Washington has consistently led on consumer data protection enforcement. Contact the AG’s consumer protection division directly at atg.wa.gov.
  • U.S. Department of Health and Human Services (HHS) Office for Civil Rights: Because HealthEquity held Protected Health Information (PHI), HIPAA’s Security Rule applies. HHS OCR investigates HIPAA violations. File a complaint at hhs.gov/ocr.
  • Consumer Financial Protection Bureau (CFPB): HealthEquity is a financial services company holding payment card data and HSA account information. The CFPB has authority over financial data protection failures. File at consumerfinance.gov/complaint.
  • Securities and Exchange Commission (SEC): HealthEquity is publicly traded. The SEC’s cybersecurity disclosure rules require public companies to disclose material cybersecurity incidents. A breach affecting 4.3 million customers that took 139+ days to publicly disclose may warrant scrutiny of HealthEquity’s SEC filings from the breach period.

Direct Action: What You Can Do Right Now

  • If you have or had a HealthEquity HSA: Assume your data was exposed. Place a free credit freeze with all three major bureaus (Equifax, Experian, TransUnion) immediately. A freeze is free, reversible, and the single most effective tool against new account fraud.
  • Request your free annual credit reports from annualcreditreport.com. Review them for accounts, loans, or inquiries you did not initiate. Dispute anything unfamiliar in writing.
  • Place a fraud alert with one credit bureau (it automatically notifies the others). This requires creditors to verify your identity before opening new accounts.
  • File a complaint with the FTC at reportfraud.ftc.gov. Every complaint filed creates a documented record that regulators use to build enforcement cases. Yours matters.
  • Contact the class action law firms directly if you believe you are a member of the affected class. The attorneys of record are Marshall Olson and Hull, PC (Salt Lake City), Milberg Coleman Bryson Phillips Grossman PLLC (Chicago), and Cotchett, Pitre and McCarthy, LLP (Seattle). Contact information is public in the case filing.
  • Connect with local mutual aid networks and credit unions in your area. Credit unions are member-owned, not-for-profit, and subject to different regulatory frameworks than corporate HSA administrators. They are a structural alternative to giving your most sensitive data to companies like HealthEquity.
  • Support data privacy legislation in your state. Contact your state representative and demand comprehensive consumer data protection law with private right of action, so that individual citizens can sue companies for data security failures directly, without waiting for a class action to wind through federal court for years.

The source document for this investigation is attached below.

Explore by category

01

Antitrust

Monopolies and anti-competition tactics used to crush rivals.

View Cases →
02

Product Safety Violations

When companies sell dangerous goods, consumers pay the price.

View Cases →
03

Environmental Violations

Pollution, ecological collapse, and unchecked greed.

View Cases →
04

Labor Exploitation

Wage theft, worker abuse, and unsafe conditions.

View Cases →
05

Data Breaches & Privacy

Misuse and mishandling of personal information.

View Cases →
06

Financial Fraud & Corruption

Lies, scams, and executive impunity that distort markets.

View Cases →
07

Intellectual Property

IP theft that punishes originality and rewards copying.

View Cases →
08

Misleading Marketing

False claims that waste money and bury critical safety info.

View Cases →
Aleeia
Aleeia

I'm Aleeia, the creator of this website.

I have 6+ years of experience as an independent researcher covering corporate misconduct, sourced from legal documents, regulatory filings, and professional legal databases.

My background includes a Supply Chain Management degree from Michigan State University's Eli Broad College of Business, and years working inside the industries I now cover.

Every post on this site was either written or personally reviewed and edited by me before publication.

Learn more about my research standards and editorial process by visiting my About page

Articles: 1886