Tag: Healthcare Data

Ransomware gang starts leaking alleged stolen Change Healthcare data
News

Ransomware gang starts leaking alleged stolen Change Healthcare data

In what has been a protracted and complicated extortion process for the organization, the RansomHub gang has started to publish what they claim is corporate and patient data seized from United Health subsidiary Change Healthcare. A hack on Change Healthcare in February severely disrupted the US healthcare system by stopping physicians and pharmacists from invoicing insurance companies or filing claims. The BlackCat/ALPHV ransomware operation was ultimately found to be responsible for the attack; they subsequently claimed to have taken 6 TB of data. The BlackCat gang ended their operations after coming under more pressure from the authorities. This happened in the midst of rumors that they were committing an escape scam by obtaining the affiliate who carried out the attack's $22 m...
US govt probes if ransomware gang stole Change Healthcare data
News

US govt probes if ransomware gang stole Change Healthcare data

The UnitedHealthcare Group (UHG) subsidiary Optum, which runs the Change Healthcare platform, was the target of a ransomware attack in late February. The U.S. Department of Health and Human Services is looking into whether or not protected health information was taken in that incident. The Office for Civil Rights (OCR) of HHS is in charge of overseeing this inquiry. OCR is responsible for enforcing the Health Insurance Portability and Accountability Act (HIPAA) regulations, which guard against the disclosure of patients' health information without their knowledge or agreement. Change Healthcare's systems and services were shut down due to a cyberattack by "nation-state" hackers, which was later connected to the BlackCat (ALPHV) ransomware gang, according to a statement released by U...
Critical Flaw in NextGen’s Mirth Connect Could Expose Healthcare Data
News

Critical Flaw in NextGen’s Mirth Connect Could Expose Healthcare Data

Following the discovery of an unauthenticated remote code execution vulnerability, users of NextGen HealthCare's open-source data integration platform, Mirth Connect, are being advised to update to the most recent version. The vulnerability, identified as CVE-2023-43208, has been fixed in version 4.4.1, which was made available on October 6, 2023. According to Naveen Sunkavally of Horizon3.ai, "this is an easily exploitable, unauthenticated remote code execution vulnerability," which was reported on Wednesday. "Attackers would most likely exploit this vulnerability for initial access or to compromise sensitive healthcare data." Mirth Connect dubbed the "Swiss Army knife of healthcare integration," is a cross-platform interface engine that enables standardized data exchange and co...