‘I Will Not Rest’; ‘I Am All In’: Remarkable Breach Hearing Sees Pledges by UHG CEO, Sen. Wyden

United Healthcare Group (UHG) CEO Andrew Witty was in a board meeting on Feb. 21 when officials interrupted with the news that Change Healthcare—a clearinghouse UHG subsidiary Optum had purchased for $1.3 billion in October 2022—was in the throes of a ransomware attack.

Hackers had actually entered the system nine days earlier via a single, external “portal” that—contrary to UHG policy—was not protected with multi-factor authentication.

“The minute we knew about this, in fact, even before I’d been briefed, our team had followed the right steps and disconnected Change from all other connections because it was critical to prevent the infection [from] affecting any other provider or network in the country,” Witty recently testified before the Senate Finance Committee.[1] “That worked. We know that did not happen. So, we contained the blast radius to just Change.”

But however “contained” Witty believed the blast to be, months later, the ripples continue as UHG itself now works to identify—and notify—affected patients, who likely number in the millions. Witty described other steps UHG took after the biggest health care data breach in history, including building a new system “from scratch,” details that may prove instructive to other covered entities (CEs) and business associates (BAs). For example, Witty said he alone decided to pay a ransom to get data back but did not mention the amount, reported to be $22 million.[2]

UHG—along with providers and other customers—is still struggling to return to what Witty termed “pre-incident” operations. For their part, members of Congress and the HHS Office for Civil Rights (OCR) are eager to learn why the server was left vulnerable, if UHG will face sanctions once OCR completes the investigation it announced in March and what new laws or regulations might be needed.

At the hearing, Sen. Ron Wyden, D-Ore., Finance chair, floated the idea of creating mandatory minimum cybersecurity standards for CEs and BAs and perhaps others, a concept Witty embraced (from the witness table, at least).

Wyden also argued that because of its size—UHG is the nation’s largest insurer in terms of revenue—it is among those with “an obligation to protect their customers and to lead on this issue” and that the firm had “let the country down” by not preventing the attack and by employing inadequate recovery efforts.

Ensuring the security of health care data “is one of the most important issues I’ve taken on,” Wyden said. “The intersection of health policy, economics, and national security is now front and center. And I am all in on this.”

This document is only available to subscribers. Please log in or purchase access.
 


Would you like to read this entire article?

If you already subscribe to this publication, just log in. If not, let us send you an email with a link that will allow you to read the entire article for free. Just complete the following form.

* required field