Change Healthcare cyberattack was due to a lack of multifactor authentication, UnitedHealth CEO says

Date:

Share post:


The Change Healthcare cyberattack that disrupted health care systems nationwide earlier this year started when hackers entered a server that lacked a basic form of security: multifactor authentication.

UnitedHealth CEO Andrew Witty said Wednesday in a U.S. Senate hearing that his company, which owns Change Healthcare, is still trying to understand why the server did not have the additional protection.

His admission did not sit well with Senate Finance Committee members who spent more than two hours questioning the CEO about the attack and broader health care issues.

“This hack could have been stopped with cybersecurity 101,” Oregon Democratic Sen. Ron Wyden told Witty.

Multifactor authentication adds a second layer of security to password-protected accounts by having users enter an auto-generated code. It’s common on apps protecting sensitive data like bank accounts and meant to guard against hackers guessing passwords.

Hackers gained access to Change Healthcare in February and unleashed a ransomware attack that encrypted and froze large parts of the company’s system, Witty said. The attack disrupted payment and claims processing around the country, stressing doctor’s offices and health care systems by interfering with their ability to file claims and get paid.

While UnitedHealth quickly disconnected the affected systems to limit damage and paid a $22 million ransom, Witty said. The company is still recovering.

“We’ve literally built this platform back from scratch so that we can reassure people that there are not elements of the old attacked environment within the new technology,” Witty said.

Witty told senators that the company was in the process of upgrading Change’s technology, and he was “incredibly frustrated” to learn about the lack of multifactor authentication, which is a standard across UnitedHealth.

In March, the Office for Civil Rights said it would investigate whether protected health information was exposed and whether Change Healthcare followed laws protecting patient privacy. The company said earlier this month that personal information that could cover a “substantial portion of people in America” may have been taken in the attack. But company officials have said they see no signs that doctor charts or full medical histories were released after the attack.

Witty also told senators he was “deeply, deeply sorry,” and the company would not rest until the problem had been fixed.

Change Healthcare provides technology used to submit and process insurance claims — about 14 billion transactions a year. UnitedHealth bought Change Healthcare in a roughly $8 billion deal that closed in 2022.

___

The Associated Press Health and Science Department receives support from the Howard Hughes Medical Institute’s Science and Educational Media Group. The AP is solely responsible for all content.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Supreme Court to weigh whether regulators were heavy handed with flavored e-cigarette products

WASHINGTON -- The Supreme Court took up an e-cigarette case Tuesday, weighing Food and Drug Administration decisions...

The US will pay Moderna $176 million to develop an mRNA pandemic flu vaccine

FILE - A patient is given a flu vaccine Oct. 28, 2022, in Lynwood, Calif. On Tuesday,...

Arthur Crudup wrote the song that became Elvis' first hit. He barely got paid

FRANKTOWN, Va. -- Arthur “Big Boy” Crudup helped invent rock ‘n’ roll.His 1946 song “That’s All Right,”...

France's far-right National Rally says it will lead a government only with an absolute majority

PARIS -- The star president of France's National Rally will take the helm of government only if...

Biden administration proposes rule for workplaces to address excessive heat

WASHINGTON -- The Biden administration proposed a new rule Tuesday to address excessive heat in the workplace,...

Le Pen first had success in an ex-mining town. Her message there is now winning over French society

HENIN-BEAUMONT, France -- In the former mining town at the heart of French far-right leader Marine Le...

Biden administration provides $504 million to support 12 'tech hubs' nationwide

WASHINGTON -- The Biden administration said Tuesday that it was providing $504 million in implementation grants for...

Stock market today: Asian shares are mixed after gains on Wall Street

HONG KONG -- Asian stocks were mixed Tuesday after stocks advanced on Wall Street and yields jumped...