UnitedHealth withheld notice of the Change Healthcare data breach for months


Change Healthcare, the UnitedHealth-owned healthtech company that lost more than 100 million people’s sensitive health data of a ransomware attack last year, said Tuesday that the company was “substantially” done with notifying affected individuals about the massive data breach.

The February 2024 ransomware attack on Change Healthcare, one of the largest patient billing processors in the United States, resulted in months of outages that disrupted care throughout the US healthcare system. A data breach has also occurred the largest known theft of medical data in US history. Change Healthcare pays hackers a ransom with the goal of preventing them from publishing anything else of the stolen data, and in turn, obtained a copy of the stolen data to begin notifying the people whose information was taken.

In an update to his data breach notice on its website on Tuesday, Change Healthcare said it had “notified affected customers” for whom the company had a postal address on file. The healthcare giant said it “may not have enough addresses for all potentially affected individuals,” and that the announcement on its website is to “provide customers and individuals with information about a criminal cyberattack.”

But if you search the web for Change Healthcare’s data breach notice, you likely won’t find the webpage in search engine results.

TechCrunch’s review of the breach notification’s web page source code revealed that Change Healthcare included hidden “noindex” code in the notification, which tells search engines to ignore the web page, making it harder for anyone who searches the web for notice will find it in search results. Change Healthcare has included the “noindex” code in its data breach notification ever since at least November 20, 2024.

It is not clear why Change Healthcare has hidden the page from search engines. UnitedHealth spokesman Tyler Mason did not comment on the reason why Change Healthcare included the code to hide the data breach notification. When asked, the spokesperson was unable to provide a specific number of individuals Change Healthcare notified of the breach beyond the estimated 100 million figure shared by the US government’s health department in October 2024.

A spokeswoman for the Department of Health and Human Services’ Office of Civil Rights, which oversees federal investigations into data breaches involving protected health information, did not respond to a request for comment on the matter. .

Change Healthcare has been criticized for being slow to notify affected individuals of the breach – the company only started doing so four months after it received a copy of the stolen files. The delay in public disclosure prompted several US states, including California, Massachusetts, Nebraska and New Hampshireto intervene by informing residents to remain alert to identity theft and fraud following a data breach.

In December 2024, Nebraska brought legal action against Change Healthcare for a series of security failures that led to the breach. The state’s attorney, Mike Hilgers, said Change Healthcare’s lack of adequate notification of affected individuals leaves the state’s citizens “more vulnerable to the exploitation of sensitive personal financial, health, and identifying information.” .”



Source link

  • Related Posts

    Google has increased the price of its Workspace plans, including its AI features for free

    Google Office has partnered on Wednesday that all of the AI ​​features in Gmail, Docs, Sheets, and Meet will be available to Workspace customers at no additional cost, though the…

    What’s next for agent AI? The founder of LangChain looks at the agents around

    Join our daily and weekly newsletters for the latest updates and exclusive content on industry leading AI coverage. Learn more Agentic AI is the latest big trend in generative AI,…

    Leave a Reply

    Your email address will not be published. Required fields are marked *