• News/
  • https://www.bleepingcomputer.com/news/security/us-govt-probes-if-ransomware-gang-stole-change-healthcare-data/

US govt probes if ransomware gang stole Change Healthcare data

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 13, 2024
·
Updated

The U.S. Department of Health and Human Services is investigating whether protected health information was stolen in a ransomware attack that hit UnitedHealthcare Group (UHG) subsidiary Optum, which operates the Change Healthcare platform, in late February. This investigation is coordinated by HHS' Office for Civil Rights (OCR), which enforces the Health Insurance Portability and Accountability Act (HIPAA) rules that protect patients' health information from being disclosed without their knowledge or consent. UnitedHealth Group confirmed in late February that Change Healthcare systems and services were shut down after a cyberattack by "nation-state" hackers, which was later linked to the BlackCat (ALPHV) ransomware gang. Change Healthcare is the largest payment exchange platform used by doctors, healthcare providers, and patients in the U.S. healthcare system and by more than 70,000 pharmacies, while UHG has contracts with over 1.6 million health professionals and 8,000 healthcare facilities across all 50 U.S. states. "We cannot say this more clearly – the Change Healthcare cyberattack is the most significant and consequential incident of its kind against the U.S. health care system in history," said Rick Pollack, the President and CEO of the American Hospital Association, last week. "For nearly two weeks, this attack has made it harder for hospitals to provide patient care, fill prescriptions, submit insurance claims, and receive payment for the essential health care servic...

Read full article

Affected Software

2 affected components
UnitedHealthcare Group Optum
UnitedHealthcare Group Change Healthcare platform
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the investigation by the U.S. Department of Health and Human Services into a ransomware attack that potentially compromised protected health information related to Change Healthcare.

2

What security implications are discussed?

The article highlights the risk of sensitive health data being stolen due to ransomware attacks, affecting patient privacy and healthcare security.

3

What organizations are involved in the reported ransomware incident?

The ransomware incident involves UnitedHealthcare Group, specifically its subsidiary Optum and the Change Healthcare platform.

4

When did the ransomware attack occur?

The ransomware attack that affected Change Healthcare is reported to have happened in late February.

5

What type of data is at risk according to this investigation?

The investigation focuses on whether protected health information was stolen during the ransomware attack.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203