• News/
  • https://www.theregister.com/2024/03/14/change_healthcare_ransomware_investigation/

US to probe Change Healthcare's data protection standards as lawsuits mount

The Register
·
Connor Jones
·
Published Mar 14, 2024
·
Updated

Change Healthcare is being investigated over the alleged 6 TB data theft by the ALPHV ransomware group as it continues recovery efforts. The US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) wrote to the healthcare IT company this week informing it that a formal inquiry into its data protection practices will soon begin. The OCR cited the "unprecedented magnitude of this cyberattack" in its letter, referring to the widespread and substantial disruption the incident has had on thousands of pharmacies and hospitals across the US. Change's software is used for carrying out various critical functions including processing insurance claims, prescriptions, and billing operations. It's also the entity responsible for enforcing the data protection and privacy rules set out in the Health Insurance Portability and Accountability Act 1996. The investigation will focus on the level of compliance with these rules and whether protected health information was breached. The ALPHV/BlackCat ransomware group, which recently shut down via an exit scam, claimed responsibility for the February attack that would end up being one of its very last. It claimed to have stolen 6 TB of data, an assertion that Change Healthcare declined to confirm when asked about it. Security researchers also spotted a $22 million Bitcoin payment made to a known ALPHV crypto wallet on March 1. Change also dodged our questioning about that. It's unclear exactly what data was stolen by the crimi...

Read full article

Affected Software

3 affected components
Change Healthcare Rx Connect
Change Healthcare Rx Edit
Change Healthcare Rx Assist
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the investigation into Change Healthcare's data protection standards following a significant data theft incident.

2

What security implications are discussed?

The article highlights potential vulnerabilities in Change Healthcare's data protection measures, especially in light of the 6 TB data theft by the ALPHV ransomware group.

3

What products or software are affected?

The affected software includes Change Healthcare Rx Connect, Change Healthcare Rx Edit, and Change Healthcare Rx Assist.

4

Which government entity is conducting the investigation?

The investigation is being conducted by the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR).

5

What is the current status of Change Healthcare's recovery efforts?

Change Healthcare is actively working on recovery efforts while facing mounting lawsuits related to the data theft incident.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203