One-third of Americans could be hit by Change Healthcare cyberattack

Omar Marques | Lightrocket | Getty Images

UnitedHealth Group CEO Andrew Witty on Wednesday told lawmakers that data from an estimated one-third of Americans could have been compromised in the cyberattack on its subsidiary Change Healthcare, and that the company paid a $22 million ransom to hackers.

Witty testified in front of the Subcommittee on Oversight and Investigations, which falls under the House of Representatives’ Committee on Energy and Commerce. He said the investigation into the breach is still ongoing, so the exact number of people affected remains unknown. The one-third figure is a rough estimate.

UnitedHealth has previously said the cyberattack likely impacts a “substantial proportion of people in America,” according to an April release. The company confirmed that files containing protected health information and personally identifiable information were compromised in the breach. 

It will likely be months before UnitedHealth is able to notify individuals, given the “complexity of the data review,” the release said. The company is offering free access to identity theft protection and credit monitoring for individuals concerned about their data.

Witty also testified in front of the U.S. Senate Committee on Finance on Wednesday, when he confirmed for the first time that the company paid a $22 million ransom to the hackers that breached Change Healthcare. At the hearing before the House legislators later that afternoon, Witty said the payment was made in bitcoin.

UnitedHealth disclosed that a cyberthreat actor breached part of Change Healthcare’s information technology network late in February. The company disconnected the affected systems when the threat was detected, and the disruption has caused widespread fallout across the U.S. health-care sector.

Witty told the subcommittee in his written testimony that the cyberattackers used “compromised credentials” to infiltrate Change Healthcare’s systems on Feb. 12 and deployed a ransomware that encrypted the network nine days later.

The portal that the bad actors initially accessed was not protected by multifactor authentication, or MFA, which requires users to verify their identities in at least two different ways. 

Witty told both committees Wednesday that UnitedHealth now has MFA in place across all external-facing systems.

Don’t miss these exclusives from CNBC PRO

Source link

Related Posts

Coconut Flour Apple Cinnamon Muffins Recipe (Grain Free)

I discovered this grain-free apple cinnamon muffin recipe made with applesauce out of desperation. (Isn’t it so true that necessity is the mother of invention?) On this particular morning, I…

Read more

How to Build a Sauna In Your Backyard (& Lessons Learned the Hard Way)

Building a sauna in your backyard sounds like a dream, doesn’t it? A perfect, cozy escape from the hustle and bustle of daily life. Somewhere you can unwind, relax, and…

Read more

Homemade Baby Powder

When I first became a mom, I started to question the ingredients in everything I put on my baby. Unfortunately, there weren’t good answers to most of my questions. One…

Read more

Homemade Curry Powder Recipe (Mild & Not Too Spicy)

I never thought I liked curry powder. I’m not sure where my negative opinion came from, but I once accidentally added it to a soup and discovered I absolutely love…

Read more

Healthy Easter Basket Ideas the Whole Family Will Enjoy

Since we largely avoid candy and other processed foods, I have to get creative and come up with other Easter basket ideas each year. As kids, my brother and I…

Read more

Energy Boosting Beet Gummies

Beets are one of my favorite vegetables. I use beet root powder in homemade blush, add them to salads, and use them to make great tasting strawberry beet fruit leather….

Read more

Leave a Reply