HomeHacker FilesThe largest healthcare hack ever just happened
October 29, 2024

The largest healthcare hack ever just happened

NetworkTigers discusses details of the Change Healthcare hack released in October 2024.

Change Healthcare, a subsidiary of UnitedHealth Group (UHG), is one of the world’s largest clearinghouses for medical billing and insurance claims. It regularly processes around 40% of all medical bills worldwide, accounting for nearly 15 billion invoices and claims. What happens when such a major corporation falls victim to a ransomware hack? Unfortunately, the results are coming to light now. 

As of October 2024, Change Healthcare has revealed that approximately 100 million people have had their personal, financial, and medical data exposed in a data breach. This hack, which took place in February 2024, is now known to be the largest-ever healthcare breach reported to federal regulators. It surpasses the previous record for the largest healthcare data breach, held by Anthem in their 2015 hack that exposed data from 78.8 million people. 

Who is affected by the Change Healthcare data breach?

This cybercrime has had an unprecedented reach into the global healthcare field. Approximately 100 million people are estimated to be affected by this data breach from Change Healthcare, and more may be yet to be announced. This means that approximately 1 in 3 Americans is expected to have sensitive information entrusted to Change Healthcare and its parent company, UnitedHealth, leaked and possibly offered for sale on the dark web. 

What information was stolen? 

Personal and confidential information reported as exposed in the breach include:

  • Patient names
  • Billing addresses
  • Social Security numbers
  • Birthday dates
  • Driver’s license numbers
  • State ID numbers
  • Passport numbers
  • Primary and secondary health plans and policies
  • Insurance member and group ID numbers
  • Medicaid and Medicare government payor ID numbers
  • Billing codes
  • Account numbers

Change Healthcare is a medical billing center, so credit card information and other financial data may have also been exposed. Finally, protected medical information such as diagnoses, test results, images, providers, appointment dates, and prescription medication information has also been stolen.

Medical record theft may be the most alarming aspect of the Change Healthcare hack. Sensitive medical information is particularly prized on the dark web. Credit card numbers and addresses can be changed, but biometric information and medical history are immutable. Because of this, medical data theft has a much longer lifespan and holds its value in cybercriminal activity for longer. It can be used for identity theft, extortion, blackmail, to add legitimacy to phishing or impersonation attempts, to file false tax returns, obtain medical procedures, wrongfully apply for insurance, as well as being sold as completely fraudulent “identity kits” online for wrongdoers. 

Timeline of the Change Healthcare breach

As far back as 8 months ago, on February 21, 2024, Change Healthcare fell victim to a ransomware effort. On July 19, 2024, the company notified the Department of Health and Human Services Office for Civil Rights about the data breach, filing a formal report. At the time, the number of people affected was estimated to be just around 500. As of October 2024, the breach report was updated to reveal that approximately 100 million people had their personal, medical, and financial information compromised due to the breach. 

How did the Change Healthcare hack happen?

A Russian hacking group, BlackCat, has claimed responsibility for the ransomware that took down Change Healthcare. The company paid the ransom demand of $22 million in Bitcoin. However, it was not clear whether the cybercriminals could make copies of the full extent of the data and offer that information on the dark web, regardless of the ransom being paid. 

One factor contributing to the Change Healthcare breach is the lack of multifactor authentication (MFA) on company servers. When UnitedHealth acquired Change in 2022, CEO Andrew Witty testified before the House of Representatives Oversight and Investigations Subcommittee that the billing service had older cybersecurity infrastructure, including no MFA. UnitedHealth had yet to upgrade the bulk of Change Healthcare’s cybersecurity infrastructure in the two years that followed post acquisition, leaving it vulnerable to hackers’ efforts. 

What are the potential outcomes of the Change Healthcare disaster? 

Significant delays and disruptions to bill processing and insurance claim adjustments have already resulted in issues with patients seeking medical care through UnitedHealth over the past year. 

The company is also under federal investigation as to whether or not it failed to comply with the Health Insurance Portability and Accountability Act (HIPAA) rules mandating the safety and storage of confidential medical information. However, even should multiple violations be discovered, the maximum penalty for a HIPAA violation as laid out by the HITECH Act of 2009 is $1.5 million, or up to $2.1 million with adjustments for inflation. This maximum penalty applies to all standard HIPAA violations in one calendar year. Due to these limits, the federal fines that UnitedHealth Group may face because of this breach are a pittance compared to the $22 million ransom that they have already paid to the hackers. 

The company is offering credit monitoring services to affected patients facing concerns about identity theft and the unsettling loss of privacy. This service is available online and by phone at 1 (866) 262-5342. However, federal regulators are questioning if these actions will be enough. The Office of Civil Rights at the Department of Health and Human Services has opened an investigation into the Change Healthcare incident and UnitedHealth’s overall cybersecurity infrastructure regarding HIPAA-protected data. As of this year, the Biden Administration is considering additional regulations for protecting and processing HIPAA information. 

If you are among the one-third of Americans whose information has been breached by the Change Healthcare hack, consider taking steps to secure your identity today. This may include enrolling in credit monitoring, changing passwords, and notifying your financial institutions. As more lessons come to light in the wake of the Change Healthcare hack, companies and individuals are facing up to the importance of using tools like MFA and prioritizing cybersecurity measures before it’s too late.

About NetworkTigers

NetworkTigers logo

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, which built and re-architected data centers for Fortune 500 firms, NetworkTigers provides consulting and network equipment to global governmental agencies, Fortune 2000, and healthcare companies. www.networktigers.com.

Gabrielle West
Gabrielle West
Gabrielle West is an experienced tech and travel writer currently based in New York City. Her work has appeared on Ladders, Ultrahuman, and more.

Popular Articles