News: 1716415514

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Go after UnitedHealth, not us, 100+ medical groups urge Uncle Sam

(2024/05/23)


More than 100 medical industry groups have asked the Feds to make UnitedHealth Group, not them, go through the rigmarole of notifying everyone about the Change Healthcare ransomware infection.

In a letter to the US Department of Health and Human Services, 102 national and state medical associations – whose members relied on UnitedHealth's IT systems to process patient data – urged HHS Secretary Xavier Becerra to make it crystal clear that their doctors, surgeons, and other healthcare professionals should be off the hook for alerting individuals that their sensitive info was stolen in the February [1]intrusion into UnitedHealth.

They also want assurances that Change Healthcare, and not medical offices themselves, are under the microscope when it comes to the government's investigation into the incident.

[2]

In short, UnitedHealth's Change Healthcare got compromised along with people's private medical-related data, there are rules and laws on notifying patients of this kind of privacy breach, and various medical groups whose customer info was affected by this ransomware attack want UnitedHealth to take care of it all.

[3]

[4]

"We are writing to request more clarity around reporting responsibilities and assure affected providers that reporting and notification obligations will be handled by Change Healthcare," the May 20 letter signed by the American Medical Association, the American Academy of Family Physicians, and others said

[5]PDF

.

HHS' Office for Civil Rights (OCR) "should publicly state that its breach investigation and immediate efforts at remediation will be focused on Change Healthcare, and not the providers affected by Change Healthcare's breach," it continued.

[6]

This is especially important given the scope of security breach. While it's still unclear how many individuals' personal and protected health information was stolen during the February ransomware attack, we do know it's a very, very large number of Americans.

"Based on the initial targeted data sampling to date, the company has found files containing protected health information and personally identifiable information, which could cover a substantial proportion of people in America," Change Healthcare's parent company UnitedHealth [7]said in an April statement.

[8]UnitedHealth CEO: 'Decision to pay ransom was mine'

[9]UnitedHealth admits IT security breach could 'cover substantial proportion of people in America'

[10]UnitedHealth's 'egregious negligence' led to Change Healthcare ransomware infection

[11]Change Healthcare's ransomware attack costs edge toward $1B so far

The 1996 US Health Insurance Portability and Accountability Act (HIPAA), designed to protect Americans' medical records and other health-related info, requires entities to notify HHS' Office for Civil Rights, media outlets, and affected individuals about incidents in which more than 500 people's data has been compromised.

Change Healthcare is a HIPAA-covered entity, and the digital intrusion definitely affected more than 500 individuals. "Providers affected by this breach are so numerous that a specific number is not readily available," according to the letter.

It continues:

A simple affirmation from OCR, as requested herein, that UHG, as the covered entity which experienced the breach is responsible for fulfilling the attendant breach reporting and notification requirements, is badly needed to address the lack of clarity among the community of affected providers. Given UHG's statement that it is prepared to fulfill these reporting and notification requirements, it appears that it would be a quick and straightforward matter for OCR to confirm publicly that the HIPAA breach notification and reporting requirements are applicable to UHG and not to the affected providers. Given the well documented state of chaos in the provider community in the wake of this breach, OCR's silence on this point is disappointing.

When asked about the HHS letter and medical providers' concerns, a UnitedHealth spokesperson referred The Register to CEO Andrew Witty's congressional testimony on May 1.

"We will, of course, comply with legal requirements and provide notice to affected individuals, and have offered to our customers and clients to provide notice on their behalf where it is permitted," Witty told US lawmakers. "We are working closely with HHS's Office of Civil Rights to make sure our notice is effective, useful and complies with the law."

[12]

Also on May 1, Witty told US senators that the business [13]paid $22 million to the [14]extortionists , reportedly an affiliate of the BlackCat/ALPH ransomware crew.

"As chief executive officer, the decision to pay a ransom was mine," he said. "This was one of the hardest decisions I've ever had to make. And I wouldn't wish it on anyone."

Witty also confirmed to Congress that past and present US military personnel likely had their info stolen during the intrusion.

The total clean-up costs to date associated with the breach have [15]hit $872 million , and are expected to climb even higher. That's in addition to advance funding and interest-free loans UnitedHealth doled out to providers struggling to care for patients amid the disruption. This sum is said to be north of $6 billion. ®

Get our [16]Tech Resources



[1] https://www.theregister.com/2024/02/22/change_healthcare_outage/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zk6-bhH2SfrEkBf-Ssgf7wAAAEo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zk6-bhH2SfrEkBf-Ssgf7wAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zk6-bhH2SfrEkBf-Ssgf7wAAAEo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://regmedia.co.uk/2024/05/22/medical_associations_letter_hhs_change_healthcare_breach.pdf

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zk6-bhH2SfrEkBf-Ssgf7wAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2024/04/23/unitedhealth_admits_breach_substantial/

[8] https://www.theregister.com/2024/04/30/unitedhealth_ceo_ransom/

[9] https://www.theregister.com/2024/04/23/unitedhealth_admits_breach_substantial/

[10] https://www.theregister.com/2024/05/08/unitedhealths_egregious_negligence/

[11] https://www.theregister.com/2024/04/16/change_healthcares_ransomware_attack_has/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zk6-bhH2SfrEkBf-Ssgf7wAAAEo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2024/04/30/unitedhealth_ceo_ransom/

[14] https://www.theregister.com/2024/03/04/alphv_ransom_payment/

[15] https://www.theregister.com/2024/04/16/change_healthcares_ransomware_attack_has/

[16] https://whitepapers.theregister.com/



Doctor Syntax

I think the govt has a point here. The public dealt with the health care providers and entrusted them with their data. It was the providers who chose to offload work to a third party. It should be those providers who are directly responsible to their customers. I regard that as an important point of principle*.

The providers certainly have a complain against their agent who let them down and may well be entitled to demand the agent do the work on their behalf and do it for free as it was their failure.

* It may be of less significance here but its disregard in the way transatlantic GDPR responsibilities are hidden is a real problem.

If an EU data subject is failed by the US service provider for the EU company with whom the subject is dealing they're expected to take it up in a US court with the service provider which is going to raise a substantial barrier compared with taking a court action in the jurisdiction, probably their own, in which the original transaction was made.

VicMortimer

To an extent that's true, but the providers don't really get a choice.

I had no idea who Change Healthcare was until my pharmacist mentioned the problems he was having with some insurance. Mine wasn't affected, but lots of people weren't getting prescriptions.

Now, everything to do with United Healthcare needs to be destroyed, of course. But this is also the fault of other insurance companies that use the same processing system.

Individual doctors? Not so much their fault. They have to use whatever system the patient's insurance uses, and the patient often has no choice of insurance, it's picked by their employer.

US Healthcare is a huge dysfunctional mess.

eggs, meet basket

Sparkus

too big to fail, too big to investigate, too big to trust.

Having the fewest wants, I am nearest to the gods.
-- Socrates