{"id":81522,"date":"2024-03-09T10:00:28","date_gmt":"2024-03-09T10:00:28","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/03\/09\/as-change-healthcares-outage-drags-on-fears-grow-that-patient-data-could-be-released-techcrunch\/"},"modified":"2024-03-09T10:00:28","modified_gmt":"2024-03-09T10:00:28","slug":"as-change-healthcares-outage-drags-on-fears-grow-that-patient-data-could-be-released-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/03\/09\/as-change-healthcares-outage-drags-on-fears-grow-that-patient-data-could-be-released-techcrunch\/","title":{"rendered":"As Change Healthcare&#8217;s outage drags on, fears grow that patient data could be released | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\"><span class=\"featured__span-first-words\">A cyberattack at U.S.<\/span> health tech giant Change Healthcare has ground much of the U.S. healthcare system to a halt for the second week in a row.<\/p>\n<p>Hospitals have been unable to check insurance benefits of in-patient stays, handle the prior authorizations needed for patient procedures and surgeries, or process billing that pays for medical services. Pharmacies have struggled to determine how much to charge patients for prescriptions without access to their health insurance records, forcing some to pay for costly medications out of pocket with cash, with others unable to afford the costs.<\/p>\n<p>Since <a href=\"https:\/\/techcrunch.com\/2024\/02\/21\/change-healthcare-cyberattack\/\" target=\"_blank\" rel=\"noopener\">Change Healthcare shut down its network suddenly on February 21<\/a> in an effort to contain the digital intruders, some smaller healthcare providers and pharmacies are warning of crashing cash reserves as they struggle to pay their bills and staff without the steady flow of reimbursements from insurance giants.<\/p>\n<p>Change Healthcare\u2019s parent company UnitedHealth Group said <a href=\"https:\/\/www.sec.gov\/ixviewer\/ix.html?doc=\/Archives\/edgar\/data\/731766\/000073176624000085\/unh-20240221.htm\" target=\"_blank\" rel=\"noopener\">in a filing with government regulators on Friday<\/a> that the health tech company was making \u201csubstantial progress\u201d in restoring its affected systems.<\/p>\n<p>As the near-term impact of the ongoing outages on patients and providers becomes clearer, questions remain about the security of millions of people\u2019s highly sensitive medical information handled by Change Healthcare.<\/p>\n<p>From Russia, a <a href=\"https:\/\/techcrunch.com\/2024\/02\/29\/unitedhealth-change-healthcare-ransomware-alphv-blackcat-pharmacy-outages\/\" target=\"_blank\" rel=\"noopener\">prolific ransomware gang taking credit for the cyberattack<\/a> on Change Healthcare claimed \u2014 without yet publishing evidence \u2014 to have stolen enormous banks containing millions of patients\u2019 private medical data from the health tech giant\u2019s systems. In a new twist, the ransomware gang now appears to have faked its own demise and dropped off the map after receiving a ransom payment worth millions in cryptocurrency.<\/p>\n<p>If patient data has been stolen, the ramifications for the affected patients will likely be irreversible and life-lasting.<\/p>\n<p>Change Healthcare is one of the world\u2019s largest facilitators of health and medical data and patient records, handling billions of healthcare transactions annually. Since 2022, the health tech giant has been owned by UnitedHealth Group, the largest health insurance provider in the United States. Hundreds of thousands of physicians and dentists, as well as tens of thousands of pharmacies and hospitals across the U.S., rely on it to bill patients according to what their health insurance benefits permit.<\/p>\n<p>That size presents a particular risk. <a href=\"https:\/\/www.justice.gov\/opa\/pr\/justice-department-sues-block-unitedhealth-group-s-acquisition-change-healthcare\" target=\"_blank\" rel=\"noopener\">U.S. antitrust officials unsuccessfully sued to block UnitedHealth from buying Change Healthcare and merging it with its healthcare subsidiary Optum, <\/a>arguing that UnitedHealth would get an unfair competitive advantage by gaining access to \u201cabout half of all Americans\u2019 health insurance claims pass each year.\u201d<\/p>\n<p>For its part, Change Healthcare has repeatedly avoided saying so far whether patient data has been compromised in the cyberattack. That has not assuaged healthcare executives who worry that the data-related fallout of the cyberattack is yet to come.<\/p>\n<p>In <a href=\"https:\/\/www.ama-assn.org\/press-center\/press-releases\/cyberattack-jeopardizes-physician-practices-ama-demands-action\" target=\"_blank\" rel=\"noopener\">a March 1 letter to the U.S. government<\/a>, the American Medical Association warned of \u201csignificant data privacy concerns\u201d amid fears that the incident \u201ccaused extensive breaches of patient and physician information.\u201d AMA president Jesse Ehrenfeld was <a href=\"https:\/\/www.washingtonpost.com\/wellness\/2024\/03\/05\/change-healthcare-hack-prescriptions-affect\/\" target=\"_blank\" rel=\"noopener\">quoted by reporters<\/a> as saying that Change Healthcare has provided \u201cno clarity about what data was compromised or stolen.\u201d<\/p>\n<p>One cybersecurity director at a large U.S. hospital system told TechCrunch that though they are in regular contact with Change and UnitedHealth, they have heard nothing so far about the security or integrity of patient records. The cybersecurity director expressed alarm at the prospect of the hackers potentially publishing the stolen sensitive patient data online.<\/p>\n<p>This person said that Change\u2019s communications, which have gradually escalated from suggesting that data might have been exfiltrated, all the way up to acknowledging an active investigation with several incident response firms, suggest it\u2019s just a matter of time before we learn how much has been stolen, and from whom. Customers will bear part of the burden of this hack, this person said, asking not to be quoted by name as they are not authorized to speak to the press.<\/p>\n<h2>Ransomware gang pulls \u2018exit scam\u2019<\/h2>\n<p>Now, the hackers seem to have disappeared, adding to the unpredictability of the situation.<\/p>\n<p>UnitedHealth initially attributed the cyberattack to <a href=\"https:\/\/techcrunch.com\/2024\/02\/22\/unitedhealth-change-healthcare-hacked-nation-state-outage\/\" target=\"_blank\" rel=\"noopener\">unspecified government-backed hackers<\/a>, but later walked back that claim and subsequently <a href=\"https:\/\/techcrunch.com\/2024\/02\/26\/ransomware-attack-change-healthcare-prescription-pharmacy-outages\/\" target=\"_blank\" rel=\"noopener\">pointed the blame at the Russia-based ransomware and extortion cybercrime group<\/a> called ALPHV (also known as BlackCat), which has no known links to any government.<\/p>\n<p>Ransomware and extortion gangs are financially motivated and <a href=\"https:\/\/techcrunch.com\/2023\/12\/18\/why-extortion-is-the-new-ransomware-threat\/\" target=\"_blank\" rel=\"noopener\">typically employ double-extortion tactics<\/a>, first scrambling the victim\u2019s data with file-encrypting malware, then swiping a copy for themselves and threatening to publish the data online if their ransom demand is not paid.<\/p>\n<p>On March 3, an affiliate of ALPHV\/BlackCat \u2014 effectively a contractor that earns a commission for the cyberattacks they launch using the ransomware gang\u2019s malware \u2014 complained in a posting on a cybercrime forum claiming that ALPHV\/BlackCat swindled the affiliate out of their earnings. The affiliate claimed in the post that ALPHV\/BlackCat stole the $22 million ransom that Change Healthcare allegedly paid to decrypt their files and prevent data leaking, as <a href=\"https:\/\/databreaches.net\/developing-alphv-allegedly-scammed-change-healthcare-and-its-own-affiliate\/\" target=\"_blank\" rel=\"noopener\">first reported by veteran security watcher DataBreaches.net<\/a>.<\/p>\n<p>As proof of their claims, the affiliate provided <a href=\"https:\/\/www.blockchain.com\/explorer\/transactions\/BTC\/383559d4a8cf4359a748ff7dacff5b0f00d1b161595da39082b2b66a4d43856c\" target=\"_blank\" rel=\"noopener\">the exact crypto wallet address<\/a> that ALPHV\/BlackCat had used two days earlier to allegedly receive the ransom. The wallet showed a <a href=\"https:\/\/www.blockchain.com\/explorer\/transactions\/BTC\/383559d4a8cf4359a748ff7dacff5b0f00d1b161595da39082b2b66a4d43856c\" target=\"_blank\" rel=\"noopener\">single transaction worth $22 million in bitcoin at the time<\/a> of payment.<\/p>\n<p>The affiliate added that despite having lost their portion of the ransom, the stolen data is \u201cstill with us,\u201d suggesting the aggrieved affiliate still has access to reams of stolen sensitive medical and patient data.<\/p>\n<p>UnitedHealth has <a href=\"https:\/\/www.wired.com\/story\/alphv-change-healthcare-ransomware-payment\/\" target=\"_blank\" rel=\"noopener\">declined to confirm to reporters<\/a> whether it paid the hackers\u2019 ransom, instead saying the company is focused on its investigation. When TechCrunch asked UnitedHealth if it disputed the reports that it paid a ransom, a company spokesperson did not respond.<\/p>\n<p>By March 5, ALPHV\/BlackCat\u2019s website was gone in what researchers believe is an exit scam, where the hackers run off with their new fortune never to be seen again, or stay low and reform later as a new gang.<\/p>\n<p>The gang\u2019s dark web website was replaced with a splash screen purporting to be a law enforcement seizure notice. In December, a global law enforcement operation <a href=\"https:\/\/techcrunch.com\/2023\/12\/19\/alphv-blackcat-ransomware-seizure\/\" target=\"_blank\" rel=\"noopener\">took down portions of ALPHV\/BlackCat\u2019s infrastructure<\/a> but the gang returned and soon began targeting new victims. But this time, security researchers <a href=\"https:\/\/twitter.com\/fwosar\/status\/1765012408752378104\" target=\"_blank\" rel=\"noopener\">suspected<\/a> the <a href=\"https:\/\/www.reuters.com\/technology\/cybersecurity\/blackcat-ransomware-site-claims-it-was-seized-uk-law-enforcement-denies-being-2024-03-05\/\" target=\"_blank\" rel=\"noopener\">gang\u2019s own deception at play<\/a>, rather than another lawful takedown effort.<\/p>\n<p>A spokesperson for the U.K. National Crime Agency, which was involved in the initial ALPHV\/BlackCat\u2019s disruption operation last year, told TechCrunch that ALPHV\/BlackCat\u2019s ostensibly seized website \u201cis not a result of NCA activity.\u201d Other global law enforcement agencies also <a href=\"https:\/\/therecord.media\/europol-doj-nca-deny-involvement-in-alphv-blackcat-ransomware-takedown\" target=\"_blank\" rel=\"noopener\">denied involvement<\/a> in the group\u2019s sudden disappearance.<\/p>\n<p>It\u2019s not uncommon for cybercrime gangs to reform or rebrand as a way to shed reputational issues, the sort of thing one might do after being busted by law enforcement action or making off with an affiliate\u2019s illicit earnings.<\/p>\n<p>Even with a payment made, there is no guarantee that the hackers will delete the data. A recent global law enforcement action aimed at disrupting the prolific LockBit ransomware operation found that <a href=\"https:\/\/techcrunch.com\/2024\/03\/04\/should-we-ban-ransom-payments\/\" target=\"_blank\" rel=\"noopener\">the cybercrime gang did not always delete the victim\u2019s data<\/a> as it claimed it would if a ransom was paid. Companies have begun to acknowledge that <a href=\"https:\/\/techcrunch.com\/2023\/10\/31\/ransomware-victims-paying-hackers-ransom\/\" target=\"_blank\" rel=\"noopener\">paying a ransom does not guarantee the return of their files<\/a>.<\/p>\n<p>For those on the front-lines of healthcare cybersecurity, the worst-case scenario is that stolen patient records become public.<\/p>\n<p>The patient safety and economic impacts of this are going to be felt for years, the hospital cybersecurity director told TechCrunch.<\/p>\n<hr\/>\n<p><em>Do\u00a0you work at Change Healthcare, Optum or UnitedHealth and know more about the cyberattack? Get in touch on Signal and WhatsApp at +1 646-755-8849, or\u00a0<a href=\"https:\/\/techcrunch.com\/2024\/03\/09\/change-healthcare-fears-data-breach-ransomware\/mailto:zack.whittaker@techcrunch.com\" target=\"_blank\" rel=\"noopener\">by email<\/a>. You can also send files and documents via\u00a0<a href=\"https:\/\/techcrunch.com\/tips\" target=\"_blank\" rel=\"noopener\">SecureDrop<\/a>.<\/em><\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2024\/03\/09\/change-healthcare-fears-data-breach-ransomware\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A cyberattack at U.S. health tech giant Change Healthcare has ground much of the U.S. healthcare system to a halt for the second week in a row. Hospitals have been unable to check insurance benefits of in-patient stays, handle the prior authorizations needed for patient procedures and surgeries, or process billing that pays for medical [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":81523,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-81522","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/81522","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=81522"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/81522\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/81523"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=81522"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=81522"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=81522"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}