Change Healthcare Cyberattack Causes Widespread Disruptions at US Pharmacies
Ransomware attack impacts more than 100 Change Healthcare services, including benefits verification, claims submission, and prior authorization. As soon as the breach was detected, Change Healthcare took the drastic step of disconnecting its systems to prevent further damage. Retail pharmacies, some now forced to revert to manual processing, face delays, sparking concerns among patients relying on timely medication.
The AHA (American Hospital Association) has advised health systems to disconnect from Change Healthcare and Optum services. This breach, reportedly due to hackers exploiting vulnerabilities in the ConnectWise ScreenConnect remote IT platform and using LockBit malware, underscores the vulnerability of consolidated healthcare data systems.
Update: "RansomHub leaked stolen data from United Health subsidiary Change Healthcare following a BlackCat/ALPHV attack, suggesting some form of collaboration between the two." Change Healthcare paid $22 million in hopes of securing the stolen data
Incident Date
February 21, 2024
Location
Estimated Cost
> 100 healthcare service affected; prescription deliveries halted six days, 6TB data stolen; reportedly $22Million Ransom paid
Type of Malware
Threat Source
References
- (#5) The biggest cybersecurity stories of 2024
- Change Healthcare Finally Admits It Paid Ransomware Hackers $22 Million—and Still Faces a Patient Data Leak
- The Change Healthcare cyberattack is still impacting pharmacies. It’s a bigger deal than you think
- US pharmacy outage triggered by ‘Blackcat’ ransomware at UnitedHealth unit, sources say
- Cyber Siege: The Attack on Change Healthcare Echoes the Colonial Pipeline Crisis, Shaking the U.S. Healthcare Sector
Industries
Impacts
IT
