UnitedHealth Says Data of 100 Million Stolen in Change Healthcare Breach
Summary:
UnitedHealth has confirmed that over 100 million individuals had their personal and healthcare data stolen in the Change Healthcare ransomware attack, marking it as the largest healthcare data breach in recent years. CEO Andrew Witty previously warned that "maybe a third" of all Americans' health data was compromised.
The breach was linked to a February ransomware attack by the BlackCat gang, which used stolen credentials to access Change Healthcare's systems. This attack led to significant disruptions in the U.S. healthcare system, affecting claims processing and pharmacy operations. The company reported that approximately 6 TB of sensitive data was stolen, including health insurance details, medical records, billing information, and personal identifiers like Social Security numbers.
UnitedHealth acknowledged paying a ransom of $22 million to recover data, but subsequent claims by the ransomware group suggested that the data was not deleted as promised. This breach has resulted in projected losses of $2.45 billion for the first nine months of 2024.
Security Officer Comments:
The Change Healthcare data breach is significant due to its scale, impacting over 100 million individuals and marking the largest healthcare data breach in recent years. It involved sensitive personal and health information, raising serious privacy concerns and risks of identity theft. The attack disrupted essential healthcare services, delaying treatments and increasing costs for patients, while also resulting in projected losses of up to $2.45 billion for UnitedHealth.
Link(s):
https://www.bleepingcomputer.com/ne...0-million-stolen-in-change-healthcare-breach/