90 Degree Benefits, Inc. – St. Paul Data Breach
90 Degree Benefits Email Breach Affects 1,268 in Wisconsin
What happened in the 90 Degree Benefits, Inc. – St. Paul data breach?
The 90 Degree Benefits, Inc. – St. Paul data breach was reported on April 18, 2025 and affected 1,268 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in Wisconsin. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
90 Degree Benefits, Inc. – St. Paul Breach Details
Healthcare Data Breach Report: 90 Degree Benefits, Inc.
Incident Overview
90 Degree Benefits, Inc., a healthcare benefits administration company based in St. Paul, Minnesota, experienced a significant data breach involving unauthorized access to its email systems. The breach was discovered and reported on April 18, 2025, affecting 1,268 individuals across Wisconsin. The incident represents a hacking or IT-related compromise of email infrastructure, which typically serves as a central repository for sensitive healthcare and personal information within benefits administration organizations. This type of breach is particularly concerning because email systems often contain unencrypted protected health information (PHI) and personally identifiable information (PII) spanning multiple data categories.
Discovery and Response Timeline
The specific discovery date and investigation timeline have not been publicly detailed in the available breach submission data. However, the April 18, 2025 submission date indicates that 90 Degree Benefits notified the Wisconsin Attorney General's office and affected individuals within the legally mandated timeframe under Wisconsin state law and HIPAA Breach Notification Rule requirements. Organizations typically discover email-based breaches through several mechanisms: unusual account activity alerts, third-party security researchers, law enforcement notifications, or routine security audits. Upon discovery, 90 Degree Benefits would have been required to conduct a risk assessment to determine whether the breach posed a reasonable likelihood of harm to affected individuals—a critical determination that triggers notification obligations. The company's response likely included securing compromised email accounts, conducting forensic analysis to determine the scope of unauthorized access, and notifying all affected individuals and their healthcare providers as required by law.
Technical Details of Email Compromise
Email system breaches typically occur through several common attack vectors: credential compromise (phishing, password reuse, weak authentication), unpatched vulnerabilities in email servers or webmail interfaces, compromised administrative accounts, or exploitation of misconfigured security settings. Email-based breaches are particularly damaging because these systems often lack the same level of encryption and access controls as dedicated healthcare databases. Once attackers gain access to email accounts, they can potentially access months or years of historical correspondence containing sensitive patient information, claims data, financial records, and administrative communications. The fact that a business associate was involved in this breach suggests that 90 Degree Benefits may have been processing healthcare data on behalf of a covered entity (such as a health plan, employer, or healthcare provider), which means the breach likely triggered notification requirements not only to individuals but also to the affected covered entity and potentially to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights.
Organizational Context
90 Degree Benefits, Inc. operates as a healthcare benefits administration and consulting firm, providing services related to employee benefits management, benefits counseling, and healthcare plan administration. The company's St. Paul location indicates it serves the Upper Midwest region, though its client base may extend nationally. Benefits administration companies like 90 Degree Benefits typically handle sensitive information for multiple employers and health plans, meaning a single breach can affect individuals across numerous organizations and geographic areas. These companies serve as business associates under HIPAA, meaning they are contractually obligated to implement administrative, physical, and technical safeguards to protect PHI they receive, use, or maintain on behalf of covered entities. The breach of a business associate's systems is particularly significant because it may indicate gaps in the security infrastructure protecting healthcare data across multiple covered entities' operations.
Impact on Affected Individuals
The breach affected 1,268 individuals, primarily in Wisconsin based on the state designation in the breach report. These individuals likely include employees of companies that contracted with 90 Degree Benefits for benefits administration services, as well as potentially their family members covered under health plans administered by the company. The individuals affected may have had their information exposed through email communications containing benefits enrollment data, claims information, health plan details, or administrative records. Notification to affected individuals was required under Wisconsin state law (which mandates notification of breaches of personal information) and under the HIPAA Breach Notification Rule, which requires covered entities and business associates to notify individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach. The notification likely included information about the breach, the types of information exposed, steps individuals should take to protect themselves, and contact information for the organization's breach response team.
Data Exposure and Privacy Implications
Email-based breaches of benefits administration systems typically expose multiple categories of sensitive information. Individuals affected by this breach may have had access to their names, addresses, phone numbers, email addresses, Social Security numbers, dates of birth, health insurance policy numbers, claims history, medical information disclosed in benefits-related communications, financial information related to health savings accounts or flexible spending accounts, and employment information. The exposure of Social Security numbers combined with health information creates significant identity theft and medical identity theft risks. Under HIPAA, the exposure of unencrypted electronic PHI triggers a presumption of breach unless the organization can demonstrate through a risk assessment that there is a low probability that the PHI has been compromised. Given that this was a hacking incident involving email systems, such a demonstration would be difficult, making notification to all affected individuals the likely outcome.
Industry Context and Regulatory Framework
Email-based breaches represent a significant and growing category of healthcare data breaches. According to HHS Office for Civil Rights data, breaches affecting 500 or more individuals are publicly reported, and email compromise incidents consistently rank among the top breach vectors in healthcare. The HIPAA Security Rule requires covered entities and business associates to implement technical safeguards including access controls, encryption, and audit controls to protect ePHI. The Breach Notification Rule, codified at 45 CFR Parts 160 and 164, requires notification to affected individuals, covered entities (if the breached entity is a business associate), and in cases affecting 500 or more residents of a state or jurisdiction, notification to prominent media outlets and the HHS Secretary. Wisconsin's state breach notification law (Wis. Stat. § 134.98) requires notification of breaches of personal information without unreasonable delay. The involvement of a business associate in this breach underscores the importance of vendor risk management and the shared responsibility model in healthcare data protection, where covered entities must ensure their business associates maintain appropriate safeguards through Business Associate Agreements (BAAs) and ongoing monitoring.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the 90 Degree Benefits, Inc. – St. Paul Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with the bureaus to prevent unauthorized credit applications.
Review health insurance claims and explanation of benefits (EOB) statements regularly for unauthorized medical services, prescriptions, or claims. Contact your health plan immediately if you identify suspicious activity.
Change passwords for all online accounts, particularly healthcare portals, insurance accounts, and financial accounts. Use strong, unique passwords and enable multi-factor authentication where available.
Monitor financial accounts and bank statements for unauthorized transactions. Set up account alerts with your financial institutions to notify you of unusual activity.
Consider enrolling in credit monitoring or identity theft protection services, which may be offered by 90 Degree Benefits or your employer at no cost as part of breach response efforts.
Be cautious of unsolicited communications claiming to be from healthcare providers, insurance companies, or financial institutions. Verify any requests for personal information by contacting organizations directly using known phone numbers or websites.
Report any suspected identity theft or fraud to the Federal Trade Commission (FTC) at IdentityTheft.gov and file a report with local law enforcement if necessary.
Retain copies of all breach notification letters and documentation for your records, as you may need this information for credit monitoring, fraud claims, or future reference.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Wisconsin Breaches
Search all breaches reported in Wisconsin