The U.S. Department of Health and Human Services is investigating whether protected health information was stolen in a ransomware attack that hit UnitedHealthcare Group (UHG) subsidiary Optum, which operates the Change Healthcare platform, in late February. This investigation is coordinated by HHS' Office for Civil Rights (OCR), which enforces the Health Insurance Portability and Accountability Act (HIPAA) rules that protect patients' health information from being disclosed without their knowledge or consent. UnitedHealth Group confirmed in late February that Change Healthcare systems and services were shut down after a cyberattack by "nation-state" hackers, which was later linked to the BlackCat (ALPHV) ransomware gang. Change Healthcare is the largest payment exchange platform used by doctors, healthcare providers, and patients in the U.S. healthcare system and by more than 70,000 pharmacies, while UHG has contracts with over 1.6 million health professionals and 8,000 healthcare facilities across all 50 U.S. states. "We cannot say this more clearly – the Change Healthcare cyberattack is the most significant and consequential incident of its kind against the U.S. health care system in history," said Rick Pollack, the President and CEO of the American Hospital Association, last week. "For nearly two weeks, this attack has made it harder for hospitals to provide patient care, fill prescriptions, submit insurance claims, and receive payment for the essential health care servic...
US govt probes if ransomware gang stole Change Healthcare data
BleepingComputer
·Sergiu Gatlan
·Published Mar 13, 2024
·Updated
Affected Software
2 affected components
UnitedHealthcare Group Optum
UnitedHealthcare Group Change Healthcare platform
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the investigation by the U.S. Department of Health and Human Services into a ransomware attack that potentially compromised protected health information related to Change Healthcare.
2
What security implications are discussed?
The article highlights the risk of sensitive health data being stolen due to ransomware attacks, affecting patient privacy and healthcare security.
3
What organizations are involved in the reported ransomware incident?
The ransomware incident involves UnitedHealthcare Group, specifically its subsidiary Optum and the Change Healthcare platform.
4
When did the ransomware attack occur?
The ransomware attack that affected Change Healthcare is reported to have happened in late February.
5
What type of data is at risk according to this investigation?
The investigation focuses on whether protected health information was stolen during the ransomware attack.