Supply chain
β Supply Chain
Kairos Health Arizona Third-Party Breach (July 2024)
Primary Source βIncident Details
Protected Health Information Stolen in HealthEquity SharePoint Breach. HealthEquity has confirmed a breach of its SharePoint data, which included protected health information. HIPAA compliance data breaches have also been HealthEquity has confirmed a breach of its SharePoint data, which included protected health information. Data breaches have also been reported by Kairos Health Arizona and Ambulnz. HealthEquity, a Draper, UT-based financial technology, and business services company, has suffered a cyberattack that has exposed protected health information. HealthEquity provides health savings account (HSA) services and other consumer-directed benefits solutions, including health reimbursement arrangements (HRAs), and manages millions of HSAs, HRAs, and other benefit accounts. Third-party company: A Third-party vendor.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- A Third-party vendor
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2024-07-01 Breach occurred
- 2024-07-05 Publicly disclosed