The real break is not the service disruption. A public leak of member records turns a network breach into a fraud kit for impersonating insurers, providers, and support desks.
HIBP validated 2.6 million affected records from the stolen data. The exposed fields include email addresses, full names, phone numbers, government-issued IDs, health insurance information, genders, and dates of birth.
That mix gives attackers enough detail to make phishing and claims fraud look real. In a healthcare benefits network, the damage keeps going after the breach is contained because the stolen identities can be reused anywhere member data is trusted.