Get 40% Off
🚨 Volatile Markets? Find Hidden Gems for Serious Outperformance
Find Stocks Now

UnitedHealth says hackers possibly stole large number of Americans' data

Published 04/22/2024, 05:56 PM
Updated 04/22/2024, 08:05 PM
© Reuters. FILE PHOTO: A UnitedHealth Group health insurance card is seen in a wallet in this picture illustration October 14, 2019. REUTERS/Lucy Nicholson/Illustration/File Photo

By Manas Mishra and Zeba Siddiqui

(Reuters) -UnitedHealth Group said on Monday that hackers stole health and personal data of potentially a "substantial proportion" of Americans from its systems in February, as the largest U.S. health insurer scrambles to contain the damage.

The intrusion at its Change Healthcare (NASDAQ:CHNG) unit, which processes about 50% of U.S. medical claims, was one of the worst hacks to hit American healthcare and caused widespread disruption in payment to doctors and health facilities.

The disclosure suggests patients' healthcare information remains vulnerable. An initial review of the compromised data showed files with protected health information or personally identifiable information "which could cover a substantial proportion of people in America," the company said in a statement on its website.

That theft on Feb. 21 occurred despite a ransom payment.

"A ransom was paid as part of the company's commitment to do all it could to protect patient data from disclosure," UnitedHealth (NYSE:UNH) Chief Executive Andrew Witty told CNBC on Monday.

"This attack was conducted by malicious threat actors, and we continue to work with the law enforcement and multiple leading cybersecurity firms during our investigation."

Hackers usually seek sensitive data such as patient records, medical histories, or treatment plans for use in further criminal acts or ransom demands in such breaches.

While a full analysis of the breached data would take "several months," there is no evidence to suggest that doctors' charts or full medical histories of individuals were stolen, UnitedHealth said. It did not say exactly how many people's data was stolen, but that it was monitoring online forums where hackers tend to leak or trade such data packets.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

The cybercriminal gang behind the breach, known as AlphV or BlackCat, has not responded to multiple requests for comment.

Another hacker group posted 22 screenshots on the dark web for about a week, some of which contained UntiedHealth customers' protected healthcare and personal data, the company said, adding it was unaware of any other leaks at this time.

That group, which calls itself Ransomhub, told Reuters earlier that a disgruntled affiliate of Blackcat had given it the data.

Soon after the hack came to light in February, Blackcat said on its website it had stolen 8 terabytes of sensitive records from Change Healthcare - only to later delete that statement without explanation.

"We know this attack has caused concern and been disruptive for consumers and providers and we are committed to doing everything possible to help and provide support to anyone who may need it," UnitedHealth CEO Witty said in the company post.

Latest comments

So when is United Healthcare going to notify policyholders who are effected. Be nice since its been two months. Why don't these hacked companies act quicker. Maybe there should be notification laws like within 72 hours so peolle can protect themselves.
Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.