90 Degree Benefits, Inc. Data Breach
90 Degree Benefits Network Server Breach Affects 172K
What happened in the 90 Degree Benefits, Inc. data breach?
The 90 Degree Benefits, Inc. data breach was reported on June 9, 2022 and affected 172,450 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Wisconsin. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
90 Degree Benefits, Inc. Breach Details
Healthcare Data Breach Report: 90 Degree Benefits, Inc.
Opening Summary
90 Degree Benefits, Inc., a Wisconsin-based healthcare benefits administration company, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was discovered and reported to the U.S. Department of Health and Human Services on June 9, 2022, affecting approximately 172,450 individuals. The incident involved a hacking or IT-related intrusion into the company's network systems, which likely resulted in the exposure of protected health information (PHI) and personally identifiable information (PII) maintained by the organization. As a business associate to covered entities under HIPAA, 90 Degree Benefits was obligated to maintain strict security protocols and notify affected individuals of the breach.
Company Response and Investigation Timeline
Upon discovery of the unauthorized access to its network server, 90 Degree Benefits initiated an incident response protocol consistent with HIPAA breach notification requirements. The company conducted a forensic investigation to determine the scope of the breach, identify which data elements were accessed, and establish the timeline of the intrusion. The submission date of June 9, 2022, indicates that the organization completed its preliminary investigation and determined that notification to affected individuals was required under 45 CFR §164.404. The company worked with its covered entity clients and likely engaged cybersecurity forensics specialists to assess the extent of the compromise and implement remedial measures to prevent future incidents. Standard response procedures for network server breaches typically include system isolation, log analysis, access control reviews, and implementation of additional security controls.
Technical Details of the Network Server Breach
Network server breaches represent a significant category of healthcare data incidents, typically involving unauthorized access through compromised credentials, unpatched vulnerabilities, or targeted cyberattacks. When a network server is compromised, threat actors may gain access to centralized repositories of patient data, claims information, and administrative records. The location designation of "Network Server" suggests that the breach involved backend infrastructure rather than endpoint devices or portable media. This type of incident typically indicates either a remote attack vector (such as exploitation of web-facing applications, VPN vulnerabilities, or phishing-based credential compromise) or potentially an insider threat with network access. Network server breaches often go undetected for extended periods, as attackers may maintain persistent access while exfiltrating data gradually. The investigation likely involved analysis of network logs, access controls, and system configurations to determine how the unauthorized access occurred and what data was accessed during the compromise period.
Organizational Context and Operations
90 Degree Benefits, Inc. operates as a healthcare benefits administration and management company based in Wisconsin. The organization functions as a business associate under HIPAA, meaning it processes, stores, and manages protected health information on behalf of covered entities such as health plans, employers, and healthcare providers. The company's operations typically include benefits enrollment, claims processing, eligibility verification, and benefits counseling services. With 172,450 individuals affected by this breach, the organization clearly maintains substantial volumes of healthcare data across multiple client relationships. The company's regional presence in Wisconsin and multi-state operations suggest it serves as a significant intermediary in the healthcare benefits ecosystem, handling sensitive information for numerous covered entities and their beneficiaries.
Impact on Affected Individuals
Approximately 172,450 individuals had their personal and health information potentially exposed through the network server breach. This substantial number of affected persons places the incident in the regional to national significance category. Individuals affected by this breach likely included employees, retirees, and dependents covered under various health benefit plans administered by 90 Degree Benefits. The notification process, required under HIPAA's Breach Notification Rule, would have been initiated following the company's determination that a breach of unsecured PHI had occurred. Notifications typically include information about the breach, the types of data exposed, steps individuals should take to protect themselves, and contact information for the organization's breach response team. The affected individuals would have received written notice either directly from 90 Degree Benefits or through their employer or health plan, depending on the contractual relationships and notification responsibilities established in business associate agreements.
Data Security and HIPAA Compliance Implications
As a HIPAA business associate, 90 Degree Benefits was required to maintain administrative, physical, and technical safeguards to protect electronic protected health information (ePHI) in accordance with the HIPAA Security Rule (45 CFR §§164.308-164.318). Network server breaches of this magnitude suggest potential gaps in one or more safeguard categories: access controls may have been insufficient, encryption of data in transit or at rest may have been inadequate, or vulnerability management and patch management processes may have been deficient. The breach notification requirement under 45 CFR §164.404 mandates that covered entities and business associates notify affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery of a breach of unsecured PHI. The June 9, 2022 submission date represents the organization's compliance with HHS notification requirements. Network server breaches affecting over 100,000 individuals are reportable to major media outlets and the HHS Secretary, elevating the public health significance of this incident. The breach underscores the ongoing challenge healthcare organizations face in defending against sophisticated cyber threats targeting valuable healthcare data repositories.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the 90 Degree Benefits, Inc. Breach
Place a fraud alert with the three major credit bureaus (Equifax, Experian, TransUnion) by contacting one bureau, which will notify the others. This alerts creditors to verify your identity before extending credit. Consider placing a credit freeze for stronger protection, which prevents new accounts from being opened without your authorization.
Monitor your credit reports regularly for suspicious activity by obtaining free annual credit reports from www.annualcreditreport.com. Review accounts, inquiries, and personal information for unauthorized entries. Consider using credit monitoring services that provide alerts for changes to your credit file.
Review your healthcare records and insurance statements for unauthorized services, claims, or coverage changes. Contact your health plan and healthcare providers to verify that only legitimate services have been billed to your account. Request copies of your medical records to ensure they contain only accurate information about services you actually received.
Monitor your financial accounts and tax records for fraudulent activity. Review bank and credit card statements regularly for unauthorized transactions. File your tax return early to prevent criminals from filing fraudulent returns using your Social Security number. Consider placing a tax transcript lock with the IRS.
Change passwords for any online accounts related to your health insurance or healthcare providers, using strong, unique passwords. Enable multi-factor authentication where available to add an additional layer of security to your accounts.
Be cautious of unsolicited communications claiming to be from healthcare providers, insurers, or financial institutions. Verify any requests for personal information by contacting the organization directly using phone numbers or websites you know to be legitimate, rather than using contact information provided in suspicious communications.
Consider enrolling in identity theft protection or credit monitoring services if offered by 90 Degree Benefits or your employer as part of breach response efforts. These services can provide early warning of fraudulent activity.
Document all breach-related communications and keep records of any fraudulent activity discovered. This documentation may be necessary for filing disputes with creditors, insurers, or credit bureaus.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Wisconsin Breaches
Search all breaches reported in Wisconsin
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuitsTechnical Notes
90 Degree Benefits, Inc. Has 2 Reported Breaches
This organization has been involved in multiple reported data breaches.
View full breach history for 90 Degree Benefits, Inc.