Featured Article

Change Healthcare confirms ransomware hackers stole medical records on a ‘substantial proportion’ of Americans

Comment

Pages from the United Healthcare website are displayed on a computer screen, Feb. 29, 2024, in New York. UnitedHealth says files with personal information that could cover “a substantial portion of people in America” may have been taken in the cyberattack on its Change Healthcare business.
Image Credits: Patrick Sison / AP

Change Healthcare has confirmed a February ransomware attack on its systems, which brought widespread disruption to the U.S. healthcare system for weeks and resulted in the theft of medical records affecting a “substantial proportion of people in America.”

In a statement Thursday, Change Healthcare said it has begun the process of notifying affected individuals whose information was stolen during the cyberattack. 

The health tech giant, owned by U.S. insurance conglomerate UnitedHealth Group, processes patient insurance and billing for thousands of hospitals, pharmacies and medical practices across the U.S. healthcare sector. As such, the company has access to massive amounts of health information on about a third of all Americans

The cyberattack prompted the company to shut down its systems, resulting in outages and delays to thousands of healthcare providers who rely on Change, and affecting countless patients who could not obtain prescriptions or had medical care or procedures delayed. 

Change said in its latest statement that it “cannot confirm exactly” what data was stolen about each individual, and that the information may vary from person to person. 

The affected information includes personal information, such as names and addresses, dates of birth, phone numbers and email addresses, as well as government identity documents, such as Social Security numbers, driver licenses and passport numbers.

The data also includes medical records and health information, such as diagnoses, medications, test results, imaging and care and treatment plans, said Change. The hackers stole health insurance information, including plan and policy details, as well as billing, claims and payment information, which Change said includes financial and banking information. 

Change said it was still in the “late stages” of its review of the stolen data to determine what was taken and that more affected individuals may be identified. Some of the stolen information may relate to guarantors who paid healthcare bills for someone else, the company said.

The company added that affected individuals should receive notice by mail beginning late July.

The ransomware attack on Change Healthcare stands as one of the largest-ever known digital thefts of U.S. medical records. While the full impact of this data breach remains unclear, the ramifications for the millions of Americans whose private medical information was irretrievably compromised are likely incalculable.

Change said it secured a copy of the stolen dataset in March to review for identifying and notifying affected individuals, which TechCrunch previously reported was obtained in exchange for paying a ransom demand.

UnitedHealth confirmed it paid at least one ransom demand to the cybercriminal group behind the ransomware attack, known as ALPHV, in an effort to prevent the publication of the stolen files. Another hacking group called RansomHub demanded an additional payment from UnitedHealth after claiming ALPHV made off with the first ransom payment but left the stolen data with one of its affiliates — essentially a contractor — who broke in and deployed the ransomware on Change’s systems.

RansomHub subsequently published several files on its dark web leak site and threatened to sell the data to the highest bidder if another ransom wasn’t paid. 

According to UnitedHealth chief executive Andrew Witty, the hackers broke into Change Healthcare’s network using a set of stolen credentials to an internal system that was not protected with multi-factor authentication, a security feature that makes it more difficult for malicious hackers to misuse stolen passwords.

The ransomware attack cost UnitedHealth around $870 million in the first three months of the year, during which the company made $100 billion in revenue, according to the company’s earnings report. UnitedHealth is expected to report its most recent earnings in mid-July.

More TechCrunch

Featured Article

Data breach exposes millions of mSpy spyware customers

A huge batch of mSpy customer service emails dating back to 2014 were stolen in a May data breach.

Data breach exposes millions of mSpy spyware customers

Kudos founder says her company makes a disposable diaper lined with 100% cotton, unlike the major competitors.

Shark Tank-backed Kudos raises another $3M for healthier, cotton-based disposable diapers

Astra CEO Chris Kemp is already pulling out of a parking spot when he warns the person in the passenger seat that he doesn’t have a valid driver’s license. “And…

‘Wild Wild Space’ doc captures the risks and rivalries of the new space race

Although these companies’ claims are artfully couched, it’s clear that they want to express that the model sees in some sense of the word.

‘Visual’ AI models might not see anything at all

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Did you…

Lucid revs up sales, Fisker makes a deal and Uber reignites an old fight

Retro CEO Nathan Sharp isn’t worrying just yet about Google’s plan to copy his app’s experience, despite the numerous similarities.

Photo-sharing startup Retro spots Google Photos copying its idea and design

Tesla had internally planned to build the dedicated robotaxi and the $25,000 car, often referred to as the Model 2, on the same platform.

Tesla reportedly delays ‘robotaxi’ event to October

Here’s a look at what’s going to change with Siri, and what the introduction of Apple Intelligence will allow you to do with the digital assistant. 

How Apple Intelligence is changing the way you use Siri on your iPhone 

The new YouTube features include those that will automatically transform longer videos into Shorts, among others.

YouTube tempts creators with a half dozen new features for Shorts

The capital will be used to expand in Europe, the U.S. and Asia.

Exein raised $15M Series B to stop robotic arms going haywire

Last month, the company also started applying an international authentication rate for activities like sending login codes for cross-border users.

WhatsApp now allows businesses to send authentication codes to users in India

Helsing has created a new entity in Estonia and plans to spend €70 million on Baltic defense projects over the next three years.

Defense AI startup Helsing raises $487M Series C, plans Baltic expansion to combat Russian threat

Alma aims to simplify the visa process for technologists, founders and researchers by providing personal legal advisors.

Alma co-founder had such a bad immigration experience she founded a legal AI startup to fix it

WhatsApp Business is changing its per-conversation rates for businesses — a conversation is a 24-hour thread between sellers and users. The company is reducing rates for utility messages and raising…

WhatsApp Business is changing its rates for messages as it aims to reduce marketing spam

HerculesAI (formerly Zero Systems) has been working at automating professional services since 2017, originally concentrating on the legal industry. As part of that, it has actually been building large language…

HerculesAI was working with large language models long before it was cool

DeepMind has implemented Google Gemini 1.5 Pro to teach a robot to respond to commands and navigate around an office.

Watch a robot navigate the Google DeepMind offices using Gemini

What this means for the future of the Fuse line remains unclear, though the companies confirmed with TechCrunch that the Micronics branding is going away.

Formlabs acquires 3D printing startup Micronics mid-Kickstarter campaign

Medal, a startup that is better known for its video game clipping product, just announced that it has raised $13 million at a valuation of $333 million from several investors,…

Medal raises $13M as it builds out a contextual AI assistant for desktop

When early SpaceX engineer Bulent Altan and long-time investor Joram Voelklein surveyed the European space sector at the end of the 2010s, they were surprised: It looked a whole lot…

Alpine Space Ventures closes first fund to grow the space economy on both sides of the pond

People in tech often say that data is the new oil. That phrase, coined by British mathematician Clive Humby, of course implies that data is valuable. Data about a person’s…

AI-powered Regard nabs $61M to find missed illness, boost hospital revenue

Featured Article

Intel Capital backs AI construction startup that could boost Intel’s own manufacturing prospects 

Intel could be giving its burgeoning foundry ambitions a much-needed shot in the arm, as the chip giant’s venture capital arm today revealed that it’s making a “strategic” investment in an Israel- and U.K.-based AI construction startup. Intel Capital is leading a $15 million investment into Buildots, a company that…

Intel Capital backs AI construction startup that could boost Intel’s own manufacturing prospects 

The European Union has accepted commitments from Apple over how it operates Apple Pay to settle a long-running competition investigation. Commission EVP Margrethe Vestager, who heads up the EU’s competition…

EU ends Apple Pay antitrust probe with binding commitments to open up contactless payments

Joby Aviation is still a year away from commercially launching its electric air taxi designed for urban environments, but the startup is already looking toward its next chapter: intercity flight,…

Joby Aviation is betting on hydrogen-electric aircraft for regional flight

Just like in your favorite anime, this is the story of a young group of twentysomethings who started with nothing, traveled the world and ended up with a global license…

Sekai secures Naruto’s license to develop consumer apps for anime fans

Uzbekistan’s mobile-only bank TBC Bank Uzbekistan has raised $38.2 million in a fresh funding by its existing shareholders.

Uzbekistan mobile bank TBC raises $38.2M to expand its financial products

Meet Adfin, a new U.K.-based fintech startup that wants to help companies get their invoices paid — whatever it takes. Founded by two fintech experts, the company is starting with…

Adfin wants to fix bill payments for sole traders and small companies

Reliance Industries, India’s most valuable company, may consider spinning off its telecom arm Jio for a public listing as early as 2025, Jefferies said in a research note, with investors…

Reliance may list Jio at $112B valuation next year, Jefferies says

Apple has issued a new round of threat notifications to iPhone users across 98 countries, warning them of potential mercenary spyware attacks. It’s the second such alert campaign from the…

Apple warns iPhone users in 98 countries of spyware attacks

Visual effects (VFX) have emerged as essential in filmmaking and have transformed storytelling and creativity in the film industry with its diverse digital techniques. However, the high cost of VFX…

Beeble AI raises $4.75M to launch a virtual production platform for indie filmmakers

As venture capitalists continue to pour money into defense tech startups, they’re turning to a new hiring pool: ex-military officials.  

More ex-military officials are becoming VCs as defense tech investment reached $35B