Change Healthcare June 20 began notifying health care providers and other customers with patient data stolen following February’s cyberattack, the company announced. The company also expects to begin mailing letters to affected individuals in late July following a data review.  

The Department of Health and Human Services May 31 announced that hospitals and health systems could require UnitedHealth Group, the owner of Change Healthcare, to notify patients if their data was stolen during the cyberattack. The AHA and other hospital groups previously urged UHG to formally issue breach notifications on behalf of providers or customers following cyberattacks if protected health information or personally identifiable information is stolen. The Department of Veterans Affairs also recently notified 15 million patients that there was a significant breach of personal health information during the February incident. According to UHG CEO Andrew Witty’s testimony May 1 during a House Energy and Commerce Subcommittee on Oversight And Investigations hearing, it is expected that a “significant portion of the population” will be affected by the breach. This highlights the systemic risk posed by the concentration of mission critical services and health care data within UHG.

Headline
The Senate passed the Health Care Cybersecurity and Resilience Act on Sept. 30 by unanimous consent. The bipartisan bill seeks to improve coordination between…
Headline
The AHA provided comments Sept. 30 to the Senate Homeland Security and Governmental Affairs Subcommittee on Disaster Management, District of Columbia and…
AHA Cyber Intel
While we may feel inundated with alarming news about escalating cyber threats against healthcare organizations, there is also some good news. Let’s explore how…
Headline
The FBI Sept. 29 announced an arrest of one of the alleged leaders of ShinyHunters, a cybercriminal group linked to cyberattacks in the U.S. and…
Headline
The FBI and the Cybersecurity and Infrastructure Security Agency have released a fact sheet for critical infrastructure organizations on ways to reduce risk…
Headline
The AHA will host a webinar Sept. 30 at 1 p.m. ET on ways healthcare organizations can build an effective, closed-loop cybersecurity program designed…