TechCrunch News 01月15日
UnitedHealth hid its Change Healthcare data breach notice for months
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Change Healthcare在2024年遭遇大规模勒索软件攻击,导致超过1亿人的敏感健康数据泄露。尽管该公司声称已“基本”完成对受影响个人的通知,但其通知方式却备受争议。Change Healthcare在网站上发布了数据泄露通知,但通过隐藏的“noindex”代码阻止搜索引擎收录,使得公众难以搜索到该页面。此外,该公司在收到被盗数据四个月后才开始通知受影响个人,导致多个州介入并警告居民注意身份盗窃和欺诈。这一事件暴露了Change Healthcare在数据安全和信息披露方面的严重问题,并引发了公众对其处理方式的质疑。

🚨Change Healthcare遭受勒索攻击,超1亿人健康数据泄露,成为美国史上最大医疗数据盗窃案。

📢公司虽声称已基本完成通知,但通过“noindex”代码隐藏通知页面,阻碍公众搜索,引发广泛质疑。

📅数据泄露发生后四个月,Change Healthcare才开始通知受影响个人,行动迟缓,导致多州介入警示居民防范风险。

⚖️内布拉斯加州因其安全漏洞和通知不足提起法律诉讼,指责其未能充分保护公民的敏感信息。

Change Healthcare, the UnitedHealth-owned healthtech company that lost more than 100 million people’s sensitive health data in a ransomware attack last year, said on Tuesday that the company has “substantially” completed notifying affected individuals about the massive data breach.

The February 2024 ransomware attack on Change Healthcare, one of the biggest processors of patient billing in the United States, resulted in months-long outages that disrupted care across the U.S. healthcare system. The data breach also became the largest known theft of medical data in U.S. history. Change Healthcare paid the hackers a ransom with the aim of preventing them from publishing any more of the stolen data, and in exchange, obtained a copy of the stolen data to begin notifying people whose information was taken.

In an update to its data breach notice on its website on Tuesday, Change Healthcare said it has “notified its impacted customers” for whom the company has a postal address on file. The healthcare giant said it “may not have sufficient addresses for all potentially impacted individuals,” and that the website notice was to “provide customers and individuals with information about the criminal cyberattack.”

But if you search the web for the Change Healthcare data breach notice, you’re unlikely to find the webpage in search engine results.

TechCrunch’s review of the breach notice’s web page source code reveals Change Healthcare included hidden “noindex” code on the notice, which tells search engines to ignore the web page, making it more difficult for anyone searching the web for the notice to find it in search results. Change Healthcare had been including the “noindex” code on its data breach notice since at least November 20, 2024.

It’s unclear why Change Healthcare hid the page from search engines. UnitedHealth spokesperson Tyler Mason did not comment on the reason why Change Healthcare included the code to hide the data breach notice. When asked, the spokesperson was unable to provide a specific number of individuals that Change Healthcare had notified of the breach beyond the estimated 100 million number shared with the U.S. government’s health department in October 2024.

A spokesperson for the Department of Health and Human Services’ Office for Civil Rights, which oversees federal investigations of data breaches involving protected health information, did not respond to a request for comment on the matter.

Change Healthcare has been criticized for being slow to notify affected individuals of the breach — the company only started to do so four months after it had received a copy of the stolen files. The delay in public disclosure prompted several U.S. states, including California, Massachusetts, Nebraska and New Hampshire, to intervene by notifying residents to stay alert to identity theft and fraud following the data breach. 

In December 2024, Nebraska brought legal action against Change Healthcare for a string of security failings that led to the breach. The state’s attorney general, Mike Hilgers, said Change Healthcare’s lack of adequate notice to affected individuals left the state’s citizens “more vulnerable to exploitation of the sensitive personal financial, health, and identifying information.”

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

数据泄露 Change Healthcare 勒索软件 医疗数据 信息安全
相关文章