US Govt Probes if Ransomware Gang Stole Change Healthcare Data
Summary: Link(s):
The U.S. Department of Health and Human Services is investigating whether protected health information was stolen in a ransomware attack that hit UnitedHealthcare Group (UHG) subsidiary Optum, which operates the Change Healthcare platform, in late February. This investigation is coordinated by HHS' Office for Civil Rights (OCR), which enforces the Health Insurance Portability and Accountability Act (HIPAA) rules that protect patients' health information from being disclosed without their knowledge or consent. UnitedHealth Group confirmed in late February that Change Healthcare systems and services were shut down after a cyberattack by "nation-state" hackers, which was later linked to the BlackCat (ALPHV) ransomware gang.
Even though UHG has brought some of the impacted systems back online after the crippling February ransomware attack, the resulting outage is still impacting operations across the U.S. healthcare industry, with the company estimating that it will be able to revive its payments platform on March 15 and medical claims network and software on March 18. The investigation follows the BlackCat ransomware gang's claims that they stole 6TB of data from Change Healthcare's network belonging to "thousands of healthcare providers, insurance providers, pharmacies, etc.” Earlier this month, BlackCat ransomware shut down in an exit scam amidst claims that they stole the $22 million ransom paid by Optum to the operator behind the Change Healthcare attack.
Security Officer Comments:
The fallout of the ALPHAV/BlackCat ransomware attack on Change Healthcare has become the most noteworthy incident that the U.S. healthcare system has ever faced, negatively affecting the ability of UHG to provide healthcare services for over two weeks. Although a variety of data was stolen during this attack, the HHS’ OCR is solely investigating patients’ health information. In UHG’s official SEC filing for this attack, UHG stated that a nation-state threat actor was behind this attack. However, there is no official evidence that BlackCat is linked to any foreign government. It is possible that Optum will be extorted again using the original attack’s stolen data, this time by the BlackCat affiliate that was banned from the group and had his ransom stolen by other members during their recent exit scam.
Suggested Corrections:
https://www.bleepingcomputer.com/ne...ransomware-gang-stole-change-healthcare-data/