Canadian Healthcare Technology Logo
  • Issues
    • Current Print Issue
    • Print Archive
  • Advertise
    • Publishing Schedule
    • Circulation
    • Unit Sizes and Rates
    • Mechanical Requirements
    • Electronic Advertising
    • White Papers
  • Subscribe
    • Print Edition
    • e-Messenger
    • White Papers
  • Events
  • Vendors
  • About Us

Philips

AGFA 1400x150

Petal Health

Petal Health 1400x150

Privacy & Security

US hack stemmed from lack of server security

May 8, 2024


Andrew WittyWASHINGTON, DC – The Change Healthcare cyberattack that disrupted health care systems across the United States earlier this year started when hackers entered a server that lacked a basic form of security: multifactor authentication. UnitedHealth CEO Andrew Witty (pictured) said in a U.S. Senate hearing that his company, which owns Change Healthcare, is still trying to understand why the server did not have the additional protection.

His admission did not sit well with Senate Finance Committee members who spent more than two hours questioning the CEO about the attack and broader healthcare issues.

“This hack could have been stopped with cybersecurity 101,” Oregon Democratic Sen. Ron Wyden told Witty.

Multifactor authentication adds a second layer of security to password-protected accounts by having users enter an auto-generated code. It’s common on apps protecting sensitive data like bank accounts and meant to guard against hackers guessing passwords.

Change Healthcare provides technology used to submit and process billions of insurance claims a year. Hackers gained access in February and unleashed a ransomware attack that encrypted and froze large parts of the company’s system, Witty said.

The attack triggered a disruption of payment and claims processing around the country, stressing doctor’s offices and healthcare systems by interfering with their ability to file claims and get paid.

UnitedHealth quickly disconnected the affected systems to limit damage and paid a $22 million ransom, Witty said. The company is still recovering.

“We’ve literally built this platform back from scratch so that we can reassure people that there are not elements of the old, attacked environment within the new technology,” Witty said, also noting that he was “deeply, deeply sorry” for the attack.

The CEO also told senators that all of the company’s core systems were now fully functional. That included claims payment and pharmacy processing.

Witty said his company had been in the process of upgrading technology for Change, which it acquired in 2022, and he was “incredibly frustrated” to learn about the lack of multifactor authentication, which is a standard across UnitedHealth.

In March, the Office for Civil Rights said it would investigate whether protected health information was exposed and whether Change Healthcare followed laws protecting patient privacy.

The company said in April that personal information that could cover a “substantial portion of people in America” may have been taken in the attack.

Company officials have said they see no signs that doctor charts or full medical histories were released after the attack. But they also have noted that it may take several months of analysis to identify and notify those who were affected. UnitedHealth is offering free credit monitoring and identity theft protection for two years.

UnitedHealth Group runs one of the nation’s largest insurers and pharmacy benefits managers. It also provides care and technology services, which include the Change business.

Cybersecurity experts say ransomware attacks have increased substantially in recent years, especially in the healthcare sector.

Witty told senators on Wednesday that his company is “consistently” under attack.

SOURCE: The Canadian Press

PreviousNext

CHT print

CHT print

e-Messenger

  • Niagara Health to deploy top-flight CT scanners
  • BC extends cost-reduction search to regional authorities
  • Osler uses Sectra’s AI service to enhance patient care
  • Waypoint Centre to deploy A4i platform
  • Island Health brings virtual psychiatry to rural communities
More from e-Messenger

Subscribe

Subscribe

Weekly blasts are sent each month, via e-mail, to over 7,000 senior managers and executives in hospitals, clinics and health regions. Learn More

Infoway

Infoway

Zebra

Zebra

Zebra

Zebra

Advertise with us

Advertise with us

Sectra KLAS

Sectra KLAS

Stratford Group

Stratford Group

Pure Storage

Pure Storage

Medirex

Medirex

NIHI

NIHI

CHT print

CHT print

Advertise with us

Advertise with us

Sectra KLAS

Sectra KLAS

Stratford Group

Stratford Group

Pure Storage

Pure Storage

Medirex

Medirex

NIHI

NIHI

Contact Us

Canadian Healthcare Technology
1118 Centre Street, Suite 204
Thornhill, Ontario, Canada L4J 7R9
Tel: 905-709-2330
Fax: 905-709-2258
info2@canhealth.com

  • Quick Links
    • Current Print Issue
    • Print Archive
    • Events
    • Vendors
    • About Us
  • Advertise
    • Publishing Schedule
    • Circulation
    • Unit Sizes and Rates
    • Mechanical Requirements
    • Electronic Advertising
    • White Papers
  • Subscribe
    • Print Edition
    • e-Messenger
    • White Papers
  • Resources
    • White Papers
    • Writers’ Guidelines
    • Privacy Policy
  • Topics
    • Administrative Solutions
    • Clinical Solutions
    • Companies
    • Continuing Care
    • Diagnostics
    • Education & Training
  •  
    • Electronic Records
    • Government & Policy
    • Infrastructure
    • Innovation
    • People
    • Privacy and Security

© 2025 Canadian Healthcare Technology

The content of Canadian Healthcare Technology is subject to copyright. Reproduction in whole or in part without prior written permission is strictly prohibited. Send all requests for permission to Jerry Zeidenberg, Publisher.

Search Site

Error: Enter a search term

  • Issues
    • Current Print Issue
    • Print Archive
  • Advertise
    • Publishing Schedule
    • Circulation
    • Unit Sizes and Rates
    • Mechanical Requirements
    • Electronic Advertising
    • White Papers
  • Subscribe
    • Print Edition
    • e-Messenger
    • White Papers
  • Events
  • Vendors
  • About Us