The US government is now investigating the Change Healthcare cyberattack

Healthcare
Image Credit: Shutterstock (Image credit: Shutterstock)

The US government is now investigating the recent Change Healthcare cyberattack in order to establish whether or not sensitive customer and patient data was stolen.

The investigation is coordinated by the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR), which is tasked with enforcing the Health Insurance Portability and Accountability Act (HIPAA), whose goal is to ensure that private patient data remains private (unless the patients agree otherwise). 

The company posted a short announcement on its status update website, saying a problem has been identified. “Some applications are currently unavailable,” the company said. “Optum is currently triaging the issue and will provide further updates as they are available.” Change Healthcare merged with Optum two years ago, in a $7.8 billion deal. 

BlackCat's rugpull

The disruption affected more than just Change. Local Michigan media, for example, reported that pharmacies were experiencing outages as a result of the attack. Scheurer Health announced, via Facebook, that it was unable to process prescriptions through patient insurance due to the “nationwide outage from the largest prescription processor in North America.”

Earlier this week, BleepingComputer said the outage was still impacting operations across the U.S. healthcare industry. The UnitedHealthcare Group (UHG), Change Healthcare’s parent company, expects to revive its payments platform on March 15, and medical claims network and software on March 18. 

"Given the unprecedented magnitude of this cyberattack, and in the best interest of patients and health care providers, OCR is initiating an investigation into this incident," said OCR head Melanie Fontes Rainer. "OCR's investigation of Change Healthcare and UHG will focus on whether a breach of protected health information occurred and Change Healthcare's and UHG's compliance with the HIPAA Rules."

In the aftermath of the attack, the notorious ransomware operator BlackCat abruptly shut down all operations and called it quits. An affiliate came forward, saying they were the ones breaching Change Healthcare, and that they forced the firm to pay $22 million in ransom to keep roughly 4TB of sensitive data private. BlackCat, instead of paying the affiliate their share, allegedly took the money and ran. The affiliate is now apparently stuck with terabytes of sensitive Change Healthcare information. 

More from TechRadar Pro

  • Change Healthcare hit by major cyberattack — US health tech giant sees website taken offline, login pages unavailable
  • Here's a list of the best firewalls around today
  • These are the best endpoint security tools right now

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Lock on Laptop Screen
United Healthcare data breach may have affected 190 million Americans
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
healthcare
US government wants to toughen up cybersecurity rules for healthcare organizations
security
Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen
ransomware avast
The biggest addiction treatment provider in the US says it was hit by data breach
healthcare
Over a million clinical records exposed in data breach
Latest in Security
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Latest in News
Buzz Lightyear Space Ranger Spin Rennovations
Disney’s giving a classic Buzz Lightyear ride a tech overhaul – here's everything you need to know
Hisense U8 series TV on wall in living room
Hisense announces 2025 mini-LED TV lineup, with screen sizes up to 100 inches – and a surprising smart TV switch
Nintendo Music teaser art
Nintendo Music expands its library with songs from Kirby and the Forgotten Land and Tetris
Opera AI Tabs
Opera's new AI feature brings order to your browser tab chaos
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead