TechCrunch News 2024年12月19日
Nebraska sues Change Healthcare over security failings that led to medical data breach of over 100 million Americans
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

内布拉斯加州起诉医疗科技巨头Change Healthcare,指控其安全措施不力导致大规模数据泄露,泄露了至少1亿美国人的敏感健康信息。此次事件源于今年2月的勒索软件攻击,黑客利用低级客服员工的用户名和密码侵入系统,并在九天内窃取了大量数据。内布拉斯加州检察长认为,Change Healthcare未能实施基本安全保护措施,导致攻击范围扩大,并指责该公司延迟通知受影响的居民。该州正在寻求法院判决,要求Change Healthcare赔偿内布拉斯加州居民和医疗机构的损失,并指出事件造成了广泛的运营中断,导致患者无法获得必要的药物和治疗。

🔒 Change Healthcare 因未能实施适当的安全措施而面临诉讼,导致超过 1 亿美国人的敏感医疗数据泄露,这是一起“历史性”的数据泄露事件。

⚠️ 黑客利用一名低级客服人员的泄露凭证进入系统,随后创建了具有管理员权限的账户,在长达九天的时间里,在未被察觉的情况下窃取了大量数据。

📢 内布拉斯加州检察长指责 Change Healthcare 未能及时通知受影响的居民,导致居民更易遭受敏感信息被滥用的风险,并自行发布通知来提醒居民。

💸 该诉讼还要求 Change Healthcare 赔偿内布拉斯加州居民和医疗机构的损失,这些医疗机构因保险索赔问题被迫在未收到付款的情况下提供护理,导致了广泛的运营中断。

The U.S. state of Nebraska has sued the healthtech giant Change Healthcare over a series of alleged security failings that resulted in a historical data breach exposing the sensitive health information of at least 100 million Americans. 

In a complaint filed this week, Nebraska’s attorney general Mike Hilgers claims UnitedHealth-owned Change Healthcare failed to implement proper security measures, leading to what he describes as a “historic” data breach in terms of impact and magnitude.

This comes after it was revealed in October that more than 100 million Americans had their sensitive medical data stolen during a February ransomware attack on Change Healthcare. This data included personal information such as addresses and phone numbers, health data including diagnoses, medications, treatment plans, and financial and banking data. Change Healthcare continues to notify affected individuals about the data breach, and the final number is expected to be higher than 100 million.

Hilgers said in his complaint that Change Healthcare’s “failures to implement basic security protections” exacerbated the extent of the cyberattack, which was attributed to the Russian-speaking ALPHV ransomware gang. The complaint alleges that the healthtech giant had poorly segmented IT systems that allowed the hackers to travel freely between servers, and that Change Healthcare had failed to implement multi-factor authentication on its systems, which meant they could be accessed with just a username and password.

The complaint also reveals some previously unreported information about the incident, including new details showing that the hackers gained access to Change Healthcare’s network using the username and password of a “low-level customer support employee,” which Hilgers said was posted to a Telegram group known for selling stolen credentials.

With access to this “basic, user-level” account, which did not have administrator access, Hilgers’ complaint alleges that hackers were able to break into the server that hosted Change’s medication management application, SelectRX. From there, the hackers created privileged accounts with administrator capabilities, including the ability to access and delete all files.

“For over nine days, the hacker navigated Change’s systems undetected, creating privileged administrator accounts, installing malware, and exfiltrating terabytes of sensitive data,” the complaint says, adding that the attack was only detected when files were encrypted, locking out the company from its own data.

Hilgers is also suing Change Healthcare over its alleged failure to notify affected individuals about the data breach, which he says impacted at least 575,000 Nebraskans. Hilgers says the state published its own notice alerting residents to the breach because Change Healthcare still had not provided notice to those affected until some five months after the cyberattack.

“As of the date of this complaint, the State of Nebraska believes that Defendants have still failed to provide written notice to many affected Nebraskans of the breach, leaving citizens more vulnerable to exploitation of the sensitive personal financial, health, and identifying information,” the complaint says. 

The Nebraska attorney general is asking a court to order Change Healthcare to pay damages “for the harm caused to Nebraska residents and healthcare providers,” which Hilgers says were forced to deliver care without receiving payment for insurance claims.

The incident also caused widespread operational disruptions, leaving patients without necessary medications and treatments.

UnitedHealth spokesperson Katherine Wojtecki told TechCrunch: “We believe this lawsuit is without merit and we intend to defend ourselves vigorously.” The company reiterated in its statement what it told TechCrunch in July, that Change Healthcare’s review of the stolen data was “in its final stages.”

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

数据泄露 Change Healthcare 网络安全 医疗数据 勒索软件
相关文章