90 Degree Benefits, Inc. Data Breach
90 Degree Benefits Network Server Breach Affects 175,000
What happened in the 90 Degree Benefits, Inc. data breach?
The 90 Degree Benefits, Inc. data breach was reported on February 8, 2023 and affected 175,000 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Wisconsin. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
90 Degree Benefits, Inc. Breach Details
Healthcare Data Breach Report: 90 Degree Benefits, Inc.
Opening Summary
On February 8, 2023, 90 Degree Benefits, Inc., a Wisconsin-based healthcare benefits administration company, reported a significant data breach affecting approximately 175,000 individuals. The breach resulted from unauthorized access to the company's network server infrastructure, compromising protected health information (PHI) and personally identifiable information (PII) of current and former plan members. This incident represents a substantial security failure at a business associate level, meaning the organization processes sensitive health data on behalf of covered entities such as health plans and employers.
Company Response and Investigation Timeline
90 Degree Benefits discovered the unauthorized access to its network server during routine security monitoring or incident response procedures. Upon discovery, the company initiated a comprehensive investigation to determine the scope of the breach, identify affected individuals, and assess what categories of personal information had been compromised. The organization notified affected individuals in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days following discovery of a breach. The submission date of February 8, 2023, indicates the company reported this incident to state authorities within the required timeframe. The investigation likely involved forensic analysis of network logs, access controls, and system vulnerabilities to determine how the unauthorized access occurred and what data was exposed.
Breach Mechanics and Technical Details
The breach occurred at the network server level, which typically indicates that attackers gained unauthorized access to centralized data storage systems where PHI and PII are maintained. Network server compromises often result from vulnerabilities such as unpatched software, weak authentication credentials, misconfigured firewalls, or exploitation of known security weaknesses. The scale of this incident—affecting 175,000 individuals—suggests the attackers accessed a significant portion of the company's database infrastructure rather than isolated records. Hacking incidents at this scale typically involve either sophisticated threat actors targeting healthcare data for financial gain or opportunistic attackers exploiting publicly disclosed vulnerabilities. The fact that this is classified as a hacking/IT incident rather than a loss or theft suggests the breach was discovered through digital forensics rather than physical theft of devices or documents.
Organizational Context and Operations
90 Degree Benefits, Inc. operates as a benefits administration and consulting firm based in Wisconsin. The company provides services related to employee benefits management, benefits counseling, and health plan administration for employers and health plans across multiple states. As a business associate under HIPAA, the organization is contractually obligated to implement administrative, physical, and technical safeguards to protect PHI. The company's role in the healthcare ecosystem places it in a critical position handling sensitive information for thousands of employers and their employees. The breach of a business associate's systems is particularly concerning because it may affect multiple covered entities and their beneficiaries simultaneously, creating a cascading impact across the healthcare industry.
Impact on Affected Individuals
Approximately 175,000 individuals had their personal and health information potentially compromised in this breach. Affected parties likely include current and former employees of companies that utilize 90 Degree Benefits' services, as well as their family members covered under employer-sponsored health plans. The notification process required the company to contact each affected individual with details about the breach, the types of information exposed, and recommended protective measures. Given the scale of this incident, notifications were likely distributed through multiple channels including direct mail, email, and potentially a dedicated breach notification website. The 175,000 affected individuals represent a significant population across Wisconsin and potentially other states where the company operates.
Data Exposure and Information Types
While the specific data elements exposed were not detailed in the breach submission, network server compromises at benefits administration companies typically expose multiple categories of sensitive information. Likely exposed data may include: names, Social Security numbers, dates of birth, addresses, phone numbers, email addresses, health insurance policy numbers, employer information, health plan details, claims history, medical diagnoses, treatment information, prescription data, and potentially financial account information used for benefits payments. The exposure of Social Security numbers combined with health information creates significant identity theft and fraud risks. The breadth of information typically stored on centralized network servers means that attackers likely obtained comprehensive personal profiles of affected individuals.
HIPAA Compliance and Regulatory Context
This breach triggers multiple HIPAA requirements for both 90 Degree Benefits and any covered entities with which it contracts. Under the HIPAA Breach Notification Rule, the company must notify affected individuals, the media (if more than 500 residents of a state are affected), and the U.S. Department of Health and Human Services (HHS). The breach also requires investigation into whether the company maintained adequate administrative, physical, and technical safeguards as required by the HIPAA Security Rule. Network server breaches of this magnitude often indicate deficiencies in access controls, encryption, vulnerability management, or incident response procedures. Healthcare data breaches involving network infrastructure compromises have become increasingly common, with attackers specifically targeting healthcare organizations due to the high value of health information on the dark web and the critical nature of healthcare operations that may incentivize ransom payments.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the 90 Degree Benefits, Inc. Breach
Monitor credit reports from all three bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze
Review health insurance statements and explanation of benefits (EOB) documents for unauthorized claims or services you did not receive
Change passwords for health insurance accounts and any online portals used to access benefits information
Monitor financial accounts and credit card statements for unauthorized transactions; consider placing fraud alerts with financial institutions
Be cautious of unsolicited communications claiming to be from healthcare providers or insurance companies; verify independently before providing information
Consider enrolling in credit monitoring or identity theft protection services if offered by the breached entity
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you discover fraudulent activity
Request a free credit report at AnnualCreditReport.com and review for suspicious accounts or inquiries
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Wisconsin Breaches
Search all breaches reported in Wisconsin
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuitsTechnical Notes
90 Degree Benefits, Inc. Has 2 Reported Breaches
This organization has been involved in multiple reported data breaches.
View full breach history for 90 Degree Benefits, Inc.