UnitedHealth says Change hackers stole well being knowledge on ‘substantial proportion of individuals in America’


Health insurance coverage large UnitedHealth Group has confirmed {that a} ransomware assault on its well being tech subsidiary Change Healthcare earlier this yr resulted in an enormous theft of Americans’ personal healthcare knowledge.

UnitedHealth mentioned in an announcement on Monday {that a} ransomware gang took information containing private knowledge and guarded well being info that it says might “cowl a considerable proportion of individuals in America.”

The medical health insurance large didn’t say what number of Americans are affected however mentioned the information evaluate was “prone to take a number of months” earlier than the corporate would start notifying people that their info was stolen within the cyberattack.

Change Healthcare processes insurance coverage and billing for tons of of 1000’s of hospitals, pharmacies and medical practices throughout the U.S. healthcare sector; it has entry to large quantities of well being info on about half of all Americans.

UnitedHealth mentioned it had not but seen proof that medical doctors’ charts or full medical histories had been exfiltrated from its techniques.

The admission that hackers stole Americans’ well being knowledge comes every week after a brand new hacking group started publishing parts of the stolen knowledge in an effort to extort a second ransom demand from the corporate.

The gang, which calls itself RansomHub, printed a number of information on its darkish internet leak web site containing private details about sufferers throughout an array of paperwork, a few of which included inner information associated to Change Healthcare. RansomHub mentioned it will promote the stolen knowledge except Change Healthcare pays a ransom.

RansomHub is the second gang to demand a ransom from Change Healthcare. The well being tech large reportedly paid $22 million to a Russia-based prison gang referred to as ALPHV in March, which then disappeared, stiffing the affiliate that carried out the information theft out of their portion of the ransom.

RansomHub claimed in its publish alongside the printed stolen knowledge that “we now have the information and never ALPHV.”

In its assertion Monday, UnitedHealth acknowledged the publication of a number of the information however stopped wanting claiming possession of the paperwork. “This isn’t an official breach notification,” UnitedHealth mentioned.

The Wall Street Journal reported Monday that the prison hacking affiliate of ALPHV broke into Change Healthcare’s community utilizing stolen credentials for a system that enables distant entry to its community. The hackers had been in Change Healthcare’s community for greater than every week earlier than deploying ransomware, permitting the hackers to steal vital quantities of knowledge from the corporate’s techniques.

The cyberattack at Change Healthcare started on February 21 and resulted in ongoing widespread outages at pharmacies and hospitals throughout the United States. For weeks, physicians, pharmacies and hospitals couldn’t confirm affected person advantages for meting out drugs, organizing inpatient care, or processing prior authorizations crucial for surgical procedures.

Much of the U.S. healthcare system floor to a halt, with healthcare suppliers dealing with monetary strain as backlogs develop and outages linger.

UnitedHealth reported final week that the ransomware assault has price it greater than $870 million in losses. The firm reported it made $99.8 billion in income through the first three months of the yr, faring higher than what Wall Street analysts had anticipated.

UnitedHealth CEO Andrew Witty, who acquired near $21 million in whole compensation the total yr of 2022, is ready to testify to House lawmakers on May 1.



Source hyperlink

Leave a Reply

Your email address will not be published. Required fields are marked *