October 25th, 2024

UnitedHealth says data of 100M stolen in Change Healthcare hack

UnitedHealth confirmed a ransomware attack on Change Healthcare compromised data of over 100 million individuals, including sensitive information. The breach's financial impact is projected at $2.45 billion.

Read original articleLink Icon
UnitedHealth says data of 100M stolen in Change Healthcare hack

UnitedHealth has confirmed that over 100 million individuals had their personal and healthcare data compromised in a ransomware attack on its subsidiary, Change Healthcare. This incident is now recognized as one of the largest healthcare data breaches in recent history. The breach, which occurred in February, was attributed to the BlackCat ransomware group, which exploited vulnerabilities in Change Healthcare's remote access systems. The stolen data includes sensitive information such as health insurance details, medical records, billing information, and personal identifiers like Social Security numbers. Following the attack, UnitedHealth reportedly paid a ransom of $22 million to retrieve the data, but complications arose when the ransomware group failed to delete the stolen information as promised. The financial impact of the breach has escalated, with losses projected to reach $2.45 billion for the first nine months of 2024. The U.S. Department of Health and Human Services has updated its records to reflect the scale of the breach, confirming that notifications have been sent to approximately 100 million individuals affected.

- Over 100 million individuals' data was stolen in the Change Healthcare breach.

- The breach was caused by a ransomware attack from the BlackCat group.

- Sensitive information compromised includes health insurance and personal identification data.

- UnitedHealth paid a ransom of $22 million but faced further complications with data security.

- Financial losses from the breach are projected to reach $2.45 billion.

Link Icon 11 comments
By @mlsu - 6 months
I really don't understand how this level of consolidation has been allowed in the healthcare market. I was affected by this, couldn't get prescriptions filled for 4 days. Turns out I'm not alone -- 100m people? That's 1/3rd of America's population!

There is no competition in the marketplace. We need to either nationalize them or break them up. These ransomware groups are small-time compared to a nation-state adversary in wartime. At this point it's a national security issue.

By @kevinmershon - 6 months
So would this count as 1 instance or 100M instances of HIPAA violations? Last I checked the penalty is $50k per violation...
By @Rafuino - 6 months
My kid had their first data breach at 2 months old due to a healthcare company we've never heard of having their data and losing it to hackers. This whole industry needs to be burned to the ground.
By @Evidlo - 6 months
Are they obligated to notify specific customers? How can I know if my data was in the hack?
By @azinman2 - 6 months
At what point can we sue, especially if basic security practices like 2FA are not enabled?
By @mrbluecoat - 6 months
> an expected $2.45 billion

Am I reading that ransom payout correctly? Or are "losses" divided among other things?

By @spoonfeeder006 - 6 months
I always wonder that maybe someone can convince these health companies, clinics, etc... to start using Qubes OS for their network connected office computers. Maybe that could prevent a sizeable number of these ransomware attacks?

TLDR Qubes OS is a security focused operating system that is geared towards end users. It relies on isolation via the Xen hypervisor (has much less privileged code than Linux, Windows, or Mac kernels), and uses hardware based virtualization features of the CPU as well. E.g. it prevents a compromised network card from accessing the memory of a trusted virtual machine through DMA attacks as an example

And ultimately it incorporates this isolation into a seamless user interface as well

I'm guessing the primary feature that would protect against ransomware is that it allows on to open suspicious links in disposable VMs

By @hulitu - 6 months
> UnitedHealth says data of 100M stolen in Change Healthcare hack

"Privacy matters to Change Healthcare, so we follow a privacy framework that helps us to manage and protect your personal information in the products and services we provide."

I guess this speaks for itself. /s