Get 40% Off
💰 Buffett reveals a $6.7B stake in Chubb. Copy the full portfolio for FREE with InvestingPro’s Stock Ideas toolCopy Portfolios

UnitedHealth says hackers potentially stole a third of Americans' data

Published 05/01/2024, 10:10 AM
Updated 05/01/2024, 06:00 PM
© Reuters. FILE PHOTO: The corporate logo of the UnitedHealth Group appears on the side of one of their office buildings in Santa Ana, California, U.S., April 13, 2020. REUTERS/Mike Blake/File Photo
UNH
-

By Ahmed Aboulenein and Zeba Siddiqui

WASHINGTON (Reuters) - Hackers who breached UnitedHealth's tech unit in February potentially stole a third of Americans' data, the largest U.S. health insurer's CEO told a Congressional committee on Wednesday.

Two Congressional panels grilled CEO Andrew Witty about the cyberattack on the company's Change Healthcare (NASDAQ:CHNG) unit, which processes around 50% of all medical claims in the U.S.

The breach has caused widespread disruptions in claims processing, impacting patients and providers across the country.

Witty fielded heated questions from Senators on the House Energy and Commerce Committee about the company's failure to prevent the breach and contain its fallout.

Pressed for details on the data compromised, Witty said "maybe a third" of Americans' protected health information and personally identifiable information was stolen.

"We continue to investigate the amount of data involved here," he added. "We do think it's going to be substantial."

The cybercriminal gang AlphV hacked into Change on Feb. 12 using stolen login credentials on an older server that did not have multi-factor authentication, Witty said.

"It was ... a platform which had only recently become part of the company was in the process of being upgraded," Witty said, referring to UnitedHealth's $13 billion acquisition of Change in 2022.

The platform also did not have the security measures prescribed in a joint alert issued by the FBI and U.S. cyber and health officials in December 2023 to specifically warn about AlphV, or BlackCat, targeting healthcare organisations.

UnitedHealth paid the gang around $22 million in bitcoin as ransom, Witty said, adding that however there was no guarantee that the breached data was secure and could not still be leaked. Another hacking group claiming to be an offshoot of AlphV said last month it had a copy of the data, though the company has not verified that claim.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

The Senate Finance panel probed the outsized influence of UnitedHealth - which has a market capitalization of $445 billion and annual revenue of $372 billion - on American healthcare. But Witty said the company's problems were not a threat to the broader economy.

Senator Bill Cassidy said senators on the panel "would have to ask, is the dominant role of United too dominant because it is into everything and messing up United messes up everybody?"

"My point is, the size of United becomes a it's almost a too big to fail and sure, because if it fails, it's going to bring down far more than it ordinarily would," Cassidy said.

Witty said in response, "I don't believe it is because actually despite our size, for example, we have no hospitals in America, we do not own any drug manufacturers."

Yet, Change processes medical claims for around 900,000 physicians, 33,000 pharmacies, 5,500 hospitals and 600 laboratories in the U.S.

U.S. military members' data was also stolen in the hack, Witty revealed, without saying how many of them were impacted.

Senate Finance Committee Chairman Ron Wyden called the hack a national security threat.

"I believe the bigger the company, the bigger the responsibility to protect its systems from hackers. UHG was a big target long before it was hacked," he added.

"UnitedHealth Group (NYSE:UNH) has not revealed how many patients' private medical records were stolen, how many providers went without reimbursement, and how many seniors are unable to pick up their prescriptions as a result of the hack," said Wyden.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

In letters to both congressional committees, the American Hospital Association said an internal survey of its members found that 94% of hospitals reported damage to cash flow, and more than half reported "significant or serious" financial damage due to Change's inability to process claims.

Similarly, 90% of respondents to an American Medical Association survey of doctors said they continue to lose revenue because of the hack, according to the group's written testimony to the Senate Finance Committee.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.