UnitedHealth says hackers possibly stole large amount of data


The disclosure suggests patients’ healthcare information remains vulnerable. — Reuters

NEW YORK: UnitedHealth Group says that hackers stole health and personal data of potentially a “substantial proportion” of Americans from its systems in February, as the largest US health insurer scrambles to contain the damage.

The intrusion at its Change Healthcare unit, which processes about 50% of US medical claims, was one of the worst hacks to hit American healthcare and caused widespread disruption in payment to doctors and health facilities.

The disclosure suggests patients’ healthcare information remains vulnerable.

An initial review of the compromised data showed files with protected health information or personally identifiable information “which could cover a substantial proportion of people in America”, the company said in a statement on its website.

That theft on Feb 21 occurred despite a ransom payment.

“A ransom was paid as part of the company’s commitment to do all it could to protect patient data from disclosure,” UnitedHealth chief executive officer Andrew Witty told CNBC on Monday.

“This attack was conducted by malicious threat actors, and we continue to work with the law enforcement and multiple leading cybersecurity firms during our investigation.”

Hackers usually seek sensitive data such as patient records, medical histories or treatment plans for use in further criminal acts or ransom demands in such breaches.

While a full analysis of the breached data would take “several months”, there is no evidence to suggest that doctors’ charts or full medical histories of individuals were stolen, UnitedHealth said.

It did not say exactly how many people’s data was stolen, but that it was monitoring online forums where hackers tend to leak or trade such data packets.

The cybercriminal gang behind the breach, known as AlphV or BlackCat, has not responded to multiple requests for comment.

Another hacker group posted 22 screenshots on the dark web for about a week, some of which contained UntiedHealth customers’ protected healthcare and personal data, the company said, adding it was unaware of any other leaks at this time.

That group, which calls itself Ransomhub, told Reuters earlier that a disgruntled affiliate of Blackcat had given it the data.

Soon after the hack came to light in February, Blackcat said on its website it had stolen eight terabytes of sensitive records from Change Healthcare, only to later delete that statement without explanation.

“We know this attack has caused concern and been disruptive for consumers and providers, and we are committed to doing everything possible to help and provide support to anyone who may need it,” Witty said in the company post. — Reuters

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Business News

Censuria Capital to participate in Golden Destinations' IPO
FBM KLCI rises cautiously as optimism grows over second round of Middle East peace talks
Ringgit firm at 3.94 vs US$ on US-Iran talk optimism
Trading ideas: Sentoria, Affin, HLBank, MISC, Paos, Muhibbah, LYC, BMS, Wentel, TDM, Ocean Fresh, Country Heights, Empire
AWB demand to catalyse Keyfield growth
Sum Technology secures listing underwriter
Favourable view on TSH Indonesian expansion
Ocean Fresh unit faces additional tax assessments
ISF Group on track to fulfil its full-year new job win target of RM150mil
New outlets to fuel Well Chip growth in the coming years

Others Also Read