The state of Nebraska has sued the healthtech giant "Change Healthcare" over a series of alleged security failings that resulted in a historical data breach
exposing the sensitive health information of at least 100 million Americans.
In a complaint filed this week, Nebraska’s attorney general Mike Hilgers claims #UnitedHealth-owned Change Healthcare failed to implement proper security measures,
leading to what he describes as a “historic” data breach in terms of impact and magnitude.
This comes after it was revealed in October that more than 100 million Americans had their sensitive medical data stolen during a February ransomware attack on Change Healthcare.
This data included personal information such as addresses and phone numbers, health data including diagnoses, medications, treatment plans, and financial and banking data.
Change Healthcare continues to notify affected individuals about the data breach,
and the final number is expected to be higher than 100 million.
Hilgers said in his complaint that Change Healthcare’s
“failures to implement basic security protections”
exacerbated the extent of the cyberattack,
which was attributed to the Russian-speaking #ALPHV #ransomware gang.
The complaint alleges that the healthtech giant had poorly segmented IT systems
that allowed the hackers to travel freely between servers,
and that Change Healthcare had failed to implement multi-factor authentication on its systems,
which meant they could be accessed with just a username and password.
https://techcrunch.com/2024/12/18/nebraska-sues-change-healthcare-over-security-failings-that-led-to-medical-data-breach-of-over-100-million-americans/