Change Healthcare June 20 began notifying health care providers and other customers with patient data stolen following February’s cyberattack, the company announced. The company also expects to begin mailing letters to affected individuals in late July following a data review.  

The Department of Health and Human Services May 31 announced that hospitals and health systems could require UnitedHealth Group, the owner of Change Healthcare, to notify patients if their data was stolen during the cyberattack. The AHA and other hospital groups previously urged UHG to formally issue breach notifications on behalf of providers or customers following cyberattacks if protected health information or personally identifiable information is stolen. The Department of Veterans Affairs also recently notified 15 million patients that there was a significant breach of personal health information during the February incident. According to UHG CEO Andrew Witty’s testimony May 1 during a House Energy and Commerce Subcommittee on Oversight And Investigations hearing, it is expected that a “significant portion of the population” will be affected by the breach. This highlights the systemic risk posed by the concentration of mission critical services and health care data within UHG.

Related News Articles

Headline
In his latest AHA Cyber and Risk Intel blog, Scott Gee, AHA deputy national advisor for cybersecurity and risk, explains how hospitals can prepare for and…
AHA Cyber Intel
In today’s heightened threat environment, driven by domestic and geopolitical issues, it is more critical than ever for hospitals to prepare for and mitigate…
Headline
In a statement submitted to the Senate Health, Education, Labor and Pensions Committee for a hearing today on health care cybersecurity and patient privacy,…
Headline
Cyberattacks on hospitals are urgent threats to patient safety, care delivery and public trust. In this conversation, Ajay Gupta, board chair of Trinity Health…
Headline
The Food and Drug Administration yesterday released a safety notice announcing a software patch is available to address cybersecurity vulnerabilities in…
Headline
The Cybersecurity and Infrastructure Security Agency, FBI, Department of Defense Cyber Crime Center and the National Security Agency June 30 released a fact…