1. Home
  2. Companies
  3. HSA Bank
HB

HSA Bank

About

HSA Bank manages tax-advantaged benefit accounts for 3 million individuals and 30,000 employers across the United States. Founded in 1997 as a medical savings account provider, the company added HSAs in 2004 and now operates digital platforms that handle benefits lifecycle management and personalization at scale. The threat model: securing financial and health data for millions of account holders while maintaining compliance across a regulated financial services environment that touches payroll systems, insurance carriers, and third-party administrators.

The technical stack centers on data analytics and personalized digital experiences - systems that ingest, process, and protect sensitive PII and PHI across the benefits enrollment and administration lifecycle. With 6,500 agents, brokers, and consultants accessing platform tools, the attack surface spans partner integrations, API endpoints, and client-facing portals. The security team operates in a domain where a breach doesn't just mean stolen credentials; it means compromised health records, financial accounts, and compliance violations under HIPAA and financial regulations.

The scale creates specific challenges: maintaining data integrity across millions of accounts, securing integrations with employer payroll systems, and monitoring access patterns across a distributed partner network. This is financial services security with healthcare compliance layered on top - two regulatory frameworks, one platform, and the operational demand to keep benefits administration running without interruption.

Similar companies

MB

M&T Bank Corporation

M&T Bank Corporation operates a community-focused banking franchise across the eastern United States with over $211 billion in assets, 950+ branches, and more than 17,000 employees. Founded in 1856, the institution has maintained 170 consecutive profitable quarters - over 42 straight years - while building infrastructure that combines personalized service with the technical capabilities of a large financial institution. The scale presents distinct security challenges: protecting customer data across a distributed branch network, securing commercial and retail banking platforms, and maintaining compliance across multiple regulatory frameworks in the eastern U.S. footprint. The bank's technical domains span retail banking, commercial banking, and SBA lending operations where M&T consistently ranks among the top 10 SBA lenders nationally. This creates a threat surface that includes customer-facing digital banking systems, internal commercial lending platforms, branch network endpoints, and the data pipelines connecting them. More than half of employees own company stock, which signals both organizational stability and the operational risk profile that comes with a distributed, invested workforce handling sensitive financial data daily. M&T's stated values - integrity, curiosity, candor, ownership, and collaboration - translate to operational requirements in a security context: maintaining customer trust through demonstrable data protection, building resilient systems that support both community bank agility and enterprise-grade security controls, and enabling secure collaboration across a geographically distributed organization. The bank's recognition in the top 5% by Greenwich Awards for customer experience suggests investment in user-facing technology, which requires security teams to balance protection with frictionless customer and employee access. The institution's 2024 philanthropic footprint included over $67.4 million in contributions to 4,006 nonprofits and 245,895 employee volunteer hours, indicating both the operational complexity of supporting community engagement programs and the cultural expectation that technology enables rather than restricts mission-aligned activities.

5 jobs
DB

Deutsche Bank

Deutsche Bank is a leading German global banking and financial services institution. Founded in 1870 to support German companies abroad, it is now the leading bank in Germany with a strong position in Europe, represented in 56 countries around the world. The bank operates through four client-focused divisions - Corporate Bank, Private Bank, Investment Bank and Asset Management - and maintains a large global workforce. Headquartered in Frankfurt, Deutsche Bank serves corporations, institutions and private individuals with a comprehensive range of financial services and sophisticated risk management solutions. The bank's scale is reflected by €30.1bn in revenues and a substantial asset base, including around €1.0tn in assets under management in Asset Management and €633bn in assets under management in Private Banking. It employs around 89,753 people and continues to invest in technology, research and client service to support clients across global markets. Deutsche Bank positions itself as the Global Hausbank for its clients, offering integrated financial solutions across Corporate Bank, Private Bank, Investment Bank and Asset Management. It maintains a network that spans 56 countries, remains committed to responsible growth and sustainability, and emphasizes governance and risk controls as a core part of its business. The firm has a long history spanning more than 150 years, reflects its role in Europe and beyond, and continues to evolve through digital transformation, security, and innovation to serve clients worldwide.

1 job
MB

Mox Bank

Traditional banking has left customers trapped in outdated systems with hidden fees, slow processes, and impersonal experiences. Mox Bank exists to fundamentally transform how people in Hong Kong interact with their money, leveraging digital innovation to eliminate friction and empower users with complete financial control. By combining Standard Chartered's 160+ years of banking expertise with cutting-edge technology and strategic partnerships with HKT, PCCW, and Trip.com, Mox delivers a mobile-first banking experience that puts customers first. Mox doesn't just offer a bank account - it provides a comprehensive financial ecosystem that grows with users' ambitions. From daily interest credited directly to accounts and unlimited 2% cash back on all spending, to fractional stock trading through Mox Invest and instant access to credit, every feature is designed to remove barriers to financial growth. The bank serves over 650,000 customers who have embraced this new paradigm, proving that transparent, customer-centric digital banking can deliver real value and change lives. Mox represents the future of finance where technology meets human needs, making sophisticated financial tools accessible to everyone.

1 job
TB

TF Bank

TF Bank is a fast-growing digital credit and payment platform operating in 14 European countries. Through our proprietary IT infrastructure, we develop simple and flexible payment and financing solutions for millions of customers. Since our founding in 1987, we have consistently combined growth with profitability, and following the stock market listing in 2016, this development has continued with a strong focus on scalability and automation. Today, TF Bank serves customers across Sweden, Norway, Finland, Denmark, Estonia, Latvia, Lithuania, Poland, Germany, Austria, Ireland, Netherlands, Italy, and Spain. Our three core segments - Consumer Lending, Ecommerce Solutions, and Credit Cards - deliver deposit products, unsecured consumer loans, digital payment solutions, and credit cards. With over 35 years in the consumer credit sector, TF Bank has maintained profitability throughout its operations while expanding from a Swedish base to become a pan-European provider listed on Nasdaq Stockholm.

AB

Axos Bank

We're a digital bank that's been around since before online banking was cool - we launched on July 4, 2000, as one of the first fully digital banks in the country. Our founders chose Independence Day for a reason: they wanted to break free from the traditional banking model with its expensive branches and hidden fees. Today, we've grown to over $20 billion in assets while staying true to our digital roots. We're headquartered in San Diego, but we serve customers nationwide without the burden of a costly branch network weighing us down. What we actually do is pretty straightforward: we offer checking, savings, mortgages, auto loans, and business banking through our website and mobile app. Our team builds the technology that makes banking work online - we're not just putting a mobile interface on an old bank system. We're publicly traded on the New York Stock Exchange (AX), FDIC insured, and we've been profitable for years because we don't have to pay for hundreds of physical locations. That means we can offer better rates and fewer fees to our customers.

SB

SouthState Bank

SouthState Bank operates a multi-state financial services infrastructure spanning eight states - Florida, Texas, the Carolinas, Georgia, Colorado, Alabama, Virginia, and Tennessee - serving 1.8 million customers through hundreds of branch locations and a nationwide correspondent banking division. The threat surface is substantial: consumer and commercial banking platforms, mortgage origination systems, wealth management tools, and digital banking channels all running simultaneously across a geographically distributed network with more than 5,000 employees. The attack vectors are standard for regional financials but compounded by scale - phishing campaigns targeting branch staff, credential stuffing against customer portals, ransomware risk across legacy and modern infrastructure, and the persistent challenge of securing third-party integrations in correspondent banking operations. The security posture has to account for both traditional branch banking workflows and digital tooling, which means defending everything from customer-facing mobile apps to internal systems like LaserPro and DecisionPro alongside the Microsoft Office stack. Growth through strategic mergers and acquisitions since the 1930s suggests a patchwork of acquired technology estates that need normalization - a common friction point for detection engineering and identity management. Correspondent banking adds regulatory complexity under Bank Secrecy Act and FinCEN requirements, demanding robust transaction monitoring, anomaly detection, and audit trails. The company is publicly traded on NYSE as SSB, which brings SEC disclosure obligations and makes incident response planning business-critical. Any material breach triggers reporting requirements and reputational exposure in a sector where trust is the product. For security practitioners, the environment presents the full finserv stack: endpoint protection across branch networks, SIEM correlation for fraud detection, cloud security for digital banking platforms, and the operational discipline to manage risk across a multi-state retail footprint while keeping pace with evolving regulatory frameworks.