One-third of Americans could be hit by Change Healthcare cyberattack

Omar Marques | Lightrocket | Getty Images

UnitedHealth Group CEO Andrew Witty on Wednesday told lawmakers that data from an estimated one-third of Americans could have been compromised in the cyberattack on its subsidiary Change Healthcare, and that the company paid a $22 million ransom to hackers.

Witty testified in front of the Subcommittee on Oversight and Investigations, which falls under the House of Representatives’ Committee on Energy and Commerce. He said the investigation into the breach is still ongoing, so the exact number of people affected remains unknown. The one-third figure is a rough estimate.

UnitedHealth has previously said the cyberattack likely impacts a “substantial proportion of people in America,” according to an April release. The company confirmed that files containing protected health information and personally identifiable information were compromised in the breach. 

It will likely be months before UnitedHealth is able to notify individuals, given the “complexity of the data review,” the release said. The company is offering free access to identity theft protection and credit monitoring for individuals concerned about their data.

Witty also testified in front of the U.S. Senate Committee on Finance on Wednesday, when he confirmed for the first time that the company paid a $22 million ransom to the hackers that breached Change Healthcare. At the hearing before the House legislators later that afternoon, Witty said the payment was made in bitcoin.

UnitedHealth disclosed that a cyberthreat actor breached part of Change Healthcare’s information technology network late in February. The company disconnected the affected systems when the threat was detected, and the disruption has caused widespread fallout across the U.S. health-care sector.

Witty told the subcommittee in his written testimony that the cyberattackers used “compromised credentials” to infiltrate Change Healthcare’s systems on Feb. 12 and deployed a ransomware that encrypted the network nine days later.

The portal that the bad actors initially accessed was not protected by multifactor authentication, or MFA, which requires users to verify their identities in at least two different ways. 

Witty told both committees Wednesday that UnitedHealth now has MFA in place across all external-facing systems.

Don’t miss these exclusives from CNBC PRO

Source link

Related Posts

‘Microdosing’ chocolate bars, gummies from Diamond Shruumz send more to hospital

“Microdosing” chocolate bars designed to give consumers “peace of mind” have sent more and more people to hospitals, the Food and Drug Administration (FDA) recently reported. The FDA published an…

Read more

The 4 things we’re most focused on in the stock market this week

The Nasdaq Composite inched higher Friday to claim its fifth straight record close, as new data this past week showed a continued cooling of inflation and Treasury yields retreated. For…

Read more

Dr. Anthony Fauci on pandemics, partisan critics, and “the psyche of the country”

Growing up on 13th Avenue in Dyker Heights, Brooklyn, in the 1940s and ’50s, Anthony “Tony” Fauci was the precocious son of the corner pharmacist. “They called him Doc,” he…

Read more

South Africa records first confirmed death from Mpox

A 37-year-old man in South Africa died earlier this week as a result of the Mpox virus, South Africa’s Health Minister Joe Phaahla said as he confirmed the first death…

Read more

Father’s Day 2024: High Protein Snack Options For Dads Who Love To Stay Active | Health News

Staying active as a dad comes with its unique set of challenges. Balancing work, family, and personal fitness requires not just dedication, but also smart nutrition to keep energy levels…

Read more

Akira Endo, Scholar of Statins That Reduce Heart Disease, Dies at 90

Akira Endo, a Japanese biochemist whose research on fungi helped to lay the groundwork for widely prescribed drugs that lower a type of cholesterol that contributes to heart disease, died…

Read more

Leave a Reply